A use-after-free in binder.c allows an elevation of privilege from...
Vulnerability Description
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit this vulnerability, however exploitation does require either the installation of a malicious local application or a separate vulnerability in a network facing application.Product: AndroidAndroid ID: A-141720095
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-2215
Credits & Attribution
No credits recorded in the NVD database.
References
- https://source.android.com/security/bulletin/2019-10-01
- http://seclists.org/fulldisclosure/2019/Oct/38
- http://packetstormsecurity.com/files/154911/Android-Binder-Use-After-Free.html
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20191030-01-binder-en
- https://security.netapp.com/advisory/ntap-20191031-0005/
- https://seclists.org/bugtraq/2019/Nov/11
- http://packetstormsecurity.com/files/155212/Slackware-Security-Advisory-Slackware-14.2-kernel-Updates.html
- https://usn.ubuntu.com/4186-1/
- https://lists.debian.org/debian-lts-announce/2020/01/msg00013.html
- http://packetstormsecurity.com/files/156495/Android-Binder-Use-After-Free.html
- https://lists.debian.org/debian-lts-announce/2020/03/msg00001.html
More from n/a
View All →Affected Vendor
Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.