top of page
Search
wordpartrama1974

Critical Bluetooth Vulnerability in Android (CVE-2020-0022) – BlueFrag: A Serious Risk for Android U



On November 3rd, 2019, we have reported a critical vulnerability affecting the Android Bluetooth subsystem. This vulnerability has been assigned CVE-2020-0022 and was now patched in the latest security patch from February 2020. The security impact is...


On November 3rd, 2019, INSINUATOR.org has reported a critical vulnerability affecting the Android Bluetooth subsystem. This vulnerability has been assigned CVE-2020-0022 and was now patched in the latest security patch from February 2020. The security impact is as follows:




Critical Bluetooth Vulnerability in Android (CVE-2020-0022) – BlueFrag



However there was an issue; the above blog post was dealing with ARM64 and the bluetooth daemon on the Peloton was (weirdly) 32 bit ARM. The implementation of memcpy in the ARM64 version has a quirk that allows the negative sized copy to end, which also allows the exploit to leak memory containing addresses. The 32 bit implementation did not have that quirk. Luckily at the very end of the post there was salvation: a different exploit for this vulnerability on a 32 bit device by Polo35. Instead of relying on the underflow this exploit used a zero length memcpy to read 4 bytes of uninitialized memory. 2ff7e9595c


0 views0 comments

Recent Posts

See All

Incredibox jogo completo grátis sem baixar

Incredibox: um jogo de música divertido e interativo Você ama música e quer criar suas próprias músicas com uma interface simples de...

Baixe o apk do instagram pro 2022

Download do APK do Instagram Pro 2022: Como obter os melhores recursos do Instagram de graça O Instagram é uma das plataformas de mídia...

Comments


bottom of page