PT-2020-11802 · Google · Android

Published

2020-12-01

·

Updated

2020-12-15

·

CVE-2020-0463

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Android versions 8.0 through 11
Description A possible out of bounds read due to a missing bounds check in the sdp server handle client req function of sdp server.cc could lead to remote information disclosure from the Bluetooth server. No additional execution privileges are needed, and user interaction is not required for exploitation.
Recommendations For Android versions 8.0 through 11, update to a version that includes the fix for this issue to prevent remote information disclosure.

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ASB-A-169342531
CVE-2020-0463

Affected Products

Android