PT-2020-20359 · Quram+1 · Quram Qmg Library+1
Mateusz Jurczyk
·
Published
2020-05-06
·
Updated
2024-05-21
·
CVE-2020-8899
CVSS v4.0
10
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L |
Name of the Vulnerable Software and Affected Versions
Samsung Android OS versions O(8.x) through Q(10.0)
Description
A buffer overwrite vulnerability exists in the Quram qmg library, allowing an unauthenticated attacker to trigger a heap-based buffer overflow by sending a specially crafted MMS. This can lead to arbitrary remote code execution (RCE) without any user interaction. The vulnerability can be exploited by sending a malicious image in MMS, email, or chat messages, and it affects the processing of images in QM and QG formats.
Recommendations
For Samsung Android OS versions O(8.x) through Q(10.0), consider disabling the processing of QM and QG image formats until a patch is available. Restrict access to the Quram image codec to minimize the risk of exploitation. Avoid opening suspicious MMS, email, or chat messages containing images, especially those in QM and QG formats, until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Heap Based Buffer Overflow
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Quram Qmg Library
Samsung Android