CVE-2019-2126
20.08.2019, 20:15
In ParseContentEncodingEntry of mkvparser.cc, there is a possible double free due to a missing reset of a freed pointer. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-127702368.Enginsight
| Vendor | Product | Version |
|---|---|---|
| android | 7.0 | |
| android | 7.1.1 | |
| android | 7.1.2 | |
| android | 8.0 | |
| android | 8.1 | |
| android | 9.0 | |
| canonical | ubuntu_linux | 16.04 |
| canonical | ubuntu_linux | 18.04 |
| canonical | ubuntu_linux | 19.04 |
| opensuse | leap | 15.1 |
𝑥
= Vulnerable software versions
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| aom |
| ||||||||||||||||||||||||||||
| chromium-browser |
| ||||||||||||||||||||||||||||
| firefox |
| ||||||||||||||||||||||||||||
| godot |
| ||||||||||||||||||||||||||||
| libvpx |
| ||||||||||||||||||||||||||||
| qtwebengine-opensource-src |
| ||||||||||||||||||||||||||||
| thunderbird |
|
Common Weakness Enumeration
References