Memory Corruption Vulnerability in tzdata Allocation and Deallocation Functions

Memory Corruption Vulnerability in tzdata Allocation and Deallocation Functions

CVE-2019-9290 · HIGH Severity

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In tzdata there is possible memory corruption due to a mismatch between allocation and deallocation functions. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-113039724

Learn more about our Cis Benchmark Audit For Google Android.