An issue was discovered on Samsung mobile devices with Q(10.0) software. There is arbitrary code execution in the Fingerprint Trustlet via a memory overwrite. The Samsung IDs are SVE-2019-16587, SVE-2019-16588, SVE-2019-16589 (April 2020).
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
http://security.samsungmobile.com/securityUpdate.smsb | vendor advisory |