CVE Vulnerabilities

CVE-2024-31331

Operator Precedence Logic Error

Published: Jul 09, 2024 | Modified: Jul 12, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

In setMimeGroup of PackageManagerService.java, there is a possible way to hide the service from Settings due to a logic error in the code. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.

Weakness

The product uses an expression in which operator precedence causes incorrect logic to be used.

Potential Mitigations

References