Description
In ColorOS (oppo mobile phone operating system, based on AOSP frameworks/native code position/services/surfaceflinger surfaceflinger.CPP), RGB is defined on the stack but uninitialized, so when the screenShot function to RGB value assignment, will not initialize the value is returned to the attackers, leading to values on the stack information leakage, the vulnerability can be used to bypass attackers ALSR.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-4168 | In ColorOS (oppo mobile phone operating system, based on AOSP frameworks/native code position/services/surfaceflinger surfaceflinger.CPP), RGB is defined on the stack but uninitialized, so when the screenShot function to RGB value assignment, will not initialize the value is returned to the attackers, leading to values on the stack information leakage, the vulnerability can be used to bypass attackers ALSR. |
References
History
No history.
Status: PUBLISHED
Assigner: OPPO
Published:
Updated: 2024-08-04T11:42:00.696Z
Reserved: 2020-04-16T00:00:00.000Z
Link: CVE-2020-11828
No data.
Status : Modified
Published: 2020-04-21T14:15:11.223
Modified: 2024-11-21T04:58:42.963
Link: CVE-2020-11828
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD