Candidate: CVE-2019-2212 PublicDate: 2019-11-13 18:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-2212 https://android.googlesource.com/platform/external/libcxx/+/4cebe6f1f01a34546b3b843b5267619a61bd7d39 Description: In poisson_distribution of random, there is an out of bounds read. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-139690488 Ubuntu-Description: Notes: Mitigation: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N [5.5 MEDIUM] Patches_libc++: upstream_libc++: needs-triage precise/esm_libc++: DNE trusty_libc++: ignored (out of standard support) trusty/esm_libc++: DNE xenial_libc++: not-affected (code not present) bionic_libc++: needed disco_libc++: DNE eoan_libc++: DNE focal_libc++: DNE groovy_libc++: DNE hirsute_libc++: DNE impish_libc++: DNE jammy_libc++: DNE devel_libc++: DNE Patches_llvm-toolchain-6.0: upstream_llvm-toolchain-6.0: needs-triage precise/esm_llvm-toolchain-6.0: DNE trusty_llvm-toolchain-6.0: ignored (out of standard support) trusty/esm_llvm-toolchain-6.0: DNE xenial_llvm-toolchain-6.0: not-affected (code not present) esm-infra/xenial_llvm-toolchain-6.0: not-affected (code not present) bionic_llvm-toolchain-6.0: not-affected (code not present) disco_llvm-toolchain-6.0: not-affected (code not present) eoan_llvm-toolchain-6.0: not-affected (code not present) focal_llvm-toolchain-6.0: not-affected (code not present) groovy_llvm-toolchain-6.0: DNE hirsute_llvm-toolchain-6.0: DNE impish_llvm-toolchain-6.0: DNE jammy_llvm-toolchain-6.0: DNE devel_llvm-toolchain-6.0: DNE Patches_llvm-toolchain-7.0: upstream_llvm-toolchain-7.0: needs-triage precise/esm_llvm-toolchain-7.0: DNE trusty_llvm-toolchain-7.0: ignored (out of standard support) trusty/esm_llvm-toolchain-7.0: DNE xenial_llvm-toolchain-7.0: DNE bionic_llvm-toolchain-7.0: DNE disco_llvm-toolchain-7.0: DNE eoan_llvm-toolchain-7.0: DNE focal_llvm-toolchain-7.0: DNE groovy_llvm-toolchain-7.0: DNE hirsute_llvm-toolchain-7.0: DNE impish_llvm-toolchain-7.0: DNE jammy_llvm-toolchain-7.0: DNE devel_llvm-toolchain-7.0: DNE