In append_to_verify_fifo_interleaved_ of stream_encoder.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-174302683
https://source.android.com/security/bulletin/pixel/2021-06-01
https://lists.debian.org/debian-lts-announce/2022/03/msg00022.html
https://lists.debian.org/debian-lts-announce/2022/09/msg00003.html
Source: MITRE
Published: 2021-06-22
Updated: 2022-09-30
Type: CWE-787
Base Score: 2.1
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N
Impact Score: 2.9
Exploitability Score: 3.9
Severity: LOW
Base Score: 5.5
Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Impact Score: 3.6
Exploitability Score: 1.8
Severity: MEDIUM