CVE-2024-27232

MEDIUM

asn1_common.c - Info Disclosure

Title source: llm
STIX 2.1

Description

In asn1_ec_pkey_parse of asn1_common.c, there is a possible OOB read due to a missing null check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

Scores

CVSS v3 5.5
EPSS 0.0001
EPSS Percentile 2.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-476 CWE-922
Status published
Products (1)
google/android
Published Apr 05, 2024
Tracked Since Feb 18, 2026