Integer Overflow Vulnerability in MPEG4Extractor Allows for Remote Code Execution

Integer Overflow Vulnerability in MPEG4Extractor Allows for Remote Code Execution

CVE-2019-9262 · HIGH Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In MPEG4Extractor, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution in the media extractor with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-111792351

Learn more about our Cis Benchmark Audit For Google Android.