ID

VAR-202212-0407


CVE

CVE-2022-42504


TITLE

Google  of  Android  Out-of-bounds write vulnerability in

Trust: 0.8

sources: JVNDB: JVNDB-2022-023740

DESCRIPTION

In CallDialReqData::encodeCallNumber of callreqdata.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-241232209References: N/A. Google of Android Exists in an out-of-bounds write vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. Google Pixel is a smart phone of Google (Google). Google Pixel has a buffer overflow vulnerability. An attacker can exploit this vulnerability to remotely execute arbitrary code

Trust: 2.25

sources: NVD: CVE-2022-42504 // JVNDB: JVNDB-2022-023740 // CNVD: CNVD-2023-01499 // VULMON: CVE-2022-42504

IOT TAXONOMY

category:['IoT']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2023-01499

AFFECTED PRODUCTS

vendor:googlemodel:androidscope:eqversion: -

Trust: 1.8

vendor:googlemodel:androidscope: - version: -

Trust: 0.8

vendor:googlemodel:pixelscope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2023-01499 // JVNDB: JVNDB-2022-023740 // NVD: CVE-2022-42504

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2022-42504
value: MEDIUM

Trust: 1.0

NVD: CVE-2022-42504
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2023-01499
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-202212-2242
value: MEDIUM

Trust: 0.6

CNVD: CNVD-2023-01499
severity: MEDIUM
baseScore: 6.5
vectorString: AV:L/AC:L/AU:M/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: MULTIPLE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 2.5
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

nvd@nist.gov: CVE-2022-42504
baseSeverity: MEDIUM
baseScore: 6.7
vectorString: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: HIGH
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 0.8
impactScore: 5.9
version: 3.1

Trust: 1.0

NVD: CVE-2022-42504
baseSeverity: MEDIUM
baseScore: 6.7
vectorString: CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: HIGH
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: CNVD: CNVD-2023-01499 // JVNDB: JVNDB-2022-023740 // CNNVD: CNNVD-202212-2242 // NVD: CVE-2022-42504

PROBLEMTYPE DATA

problemtype:CWE-787

Trust: 1.0

problemtype:Out-of-bounds writing (CWE-787) [NVD evaluation ]

Trust: 0.8

sources: JVNDB: JVNDB-2022-023740 // NVD: CVE-2022-42504

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-202212-2242

TYPE

buffer error

Trust: 0.6

sources: CNNVD: CNNVD-202212-2242

PATCH

title:Patch for Google Pixel Buffer Overflow Vulnerability (CNVD-2023-01499)url:https://www.cnvd.org.cn/patchInfo/show/391876

Trust: 0.6

title:Google Pixel Buffer error vulnerability fixurl:http://123.124.177.30/web/xxk/bdxqById.tag?id=218719

Trust: 0.6

sources: CNVD: CNVD-2023-01499 // CNNVD: CNNVD-202212-2242

EXTERNAL IDS

db:NVDid:CVE-2022-42504

Trust: 3.9

db:JVNDBid:JVNDB-2022-023740

Trust: 0.8

db:CNVDid:CNVD-2023-01499

Trust: 0.6

db:CNNVDid:CNNVD-202212-2242

Trust: 0.6

db:VULMONid:CVE-2022-42504

Trust: 0.1

sources: CNVD: CNVD-2023-01499 // VULMON: CVE-2022-42504 // JVNDB: JVNDB-2022-023740 // CNNVD: CNNVD-202212-2242 // NVD: CVE-2022-42504

REFERENCES

url:https://source.android.com/security/bulletin/pixel/2022-12-01

Trust: 2.5

url:https://nvd.nist.gov/vuln/detail/cve-2022-42504

Trust: 1.4

url:https://vigilance.fr/vulnerability/google-android-pixel-multiple-vulnerabilities-of-december-2022-40023

Trust: 0.6

url:https://cxsecurity.com/cveshow/cve-2022-42504/

Trust: 0.6

url:https://nvd.nist.gov

Trust: 0.1

sources: CNVD: CNVD-2023-01499 // VULMON: CVE-2022-42504 // JVNDB: JVNDB-2022-023740 // CNNVD: CNNVD-202212-2242 // NVD: CVE-2022-42504

SOURCES

db:CNVDid:CNVD-2023-01499
db:VULMONid:CVE-2022-42504
db:JVNDBid:JVNDB-2022-023740
db:CNNVDid:CNNVD-202212-2242
db:NVDid:CVE-2022-42504

LAST UPDATE DATE

2024-08-14T15:00:37.943000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2023-01499date:2023-01-08T00:00:00
db:VULMONid:CVE-2022-42504date:2022-12-16T00:00:00
db:JVNDBid:JVNDB-2022-023740date:2023-11-30T01:10:00
db:CNNVDid:CNNVD-202212-2242date:2022-12-22T00:00:00
db:NVDid:CVE-2022-42504date:2022-12-21T18:13:23.953

SOURCES RELEASE DATE

db:CNVDid:CNVD-2023-01499date:2023-01-08T00:00:00
db:VULMONid:CVE-2022-42504date:2022-12-16T00:00:00
db:JVNDBid:JVNDB-2022-023740date:2023-11-30T00:00:00
db:CNNVDid:CNNVD-202212-2242date:2022-12-05T00:00:00
db:NVDid:CVE-2022-42504date:2022-12-16T16:15:22.703