Vulnerability Description
In ColorOS (oppo mobile phone operating system, based on AOSP frameworks/native code position/services/surfaceflinger surfaceflinger.CPP), RGB is defined on the stack but uninitialized, so when the screenShot function to RGB value assignment, will not initialize the value is returned to the attackers, leading to values on the stack information leakage, the vulnerability can be used to bypass attackers ALSR.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Oppo | Coloros | - |
Related Weaknesses (CWE)
References
- https://security.oppo.com/cn/noticedetails.html?noticeId=20201587348300033Third Party Advisory
- https://security.oppo.com/cn/noticedetails.html?noticeId=20201587348300033Third Party Advisory
FAQ
What is CVE-2020-11828?
CVE-2020-11828 is a vulnerability with a CVSS score of 7.5 (HIGH). In ColorOS (oppo mobile phone operating system, based on AOSP frameworks/native code position/services/surfaceflinger surfaceflinger.CPP), RGB is defined on the stack but uninitialized, so when the sc...
How severe is CVE-2020-11828?
CVE-2020-11828 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-11828?
Check the references section above for vendor advisories and patch information. Affected products include: Oppo Coloros.