CVE-2020-0004

In generateCrop of WallpaperManagerService.java, there is a possible sysui crash due to image exceeding maximum texture size. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-120847476
References
Link Resource
https://source.android.com/security/bulletin/2020-01-01 Patch Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:google:android:8.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:8.1:*:*:*:*:*:*:*
cpe:2.3:o:google:android:9.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:10.0:*:*:*:*:*:*:*

History

01 Jan 2022, 20:01

Type Values Removed Values Added
References (CONFIRM) https://source.android.com/security/bulletin/2020-01-01 - (CONFIRM) https://source.android.com/security/bulletin/2020-01-01 - Patch, Vendor Advisory
CVSS v2 : 2.1
v3 : 5.5
v2 : 4.9
v3 : 5.5
CWE CWE-20 CWE-755

Information

Published : 2020-01-08 19:15

Updated : 2023-12-10 13:13


NVD link : CVE-2020-0004

Mitre link : CVE-2020-0004

CVE.ORG link : CVE-2020-0004


JSON object : View

Products Affected

google

  • android
CWE
CWE-755

Improper Handling of Exceptional Conditions