4.4

CVE-2023-20798

In pda, there is a possible out of bounds read due to an incorrect calculation of buffer size. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07147572; Issue ID: ALPS07421076.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Google ≫ Android Version 12.0
   Mediatek ≫ Mt2713 Version -
   Mediatek ≫ Mt6855 Version -
   Mediatek ≫ Mt6879 Version -
   Mediatek ≫ Mt6886 Version -
   Mediatek ≫ Mt6895 Version -
   Mediatek ≫ Mt6983 Version -
   Mediatek ≫ Mt6985 Version -
   Mediatek ≫ Mt8188 Version -
   Mediatek ≫ Mt8195 Version -
   Mediatek ≫ Mt8395 Version -
   Mediatek ≫ Mt8673 Version -
Google ≫ Android Version 13.0
   Mediatek ≫ Mt2713 Version -
   Mediatek ≫ Mt6855 Version -
   Mediatek ≫ Mt6879 Version -
   Mediatek ≫ Mt6886 Version -
   Mediatek ≫ Mt6895 Version -
   Mediatek ≫ Mt6983 Version -
   Mediatek ≫ Mt6985 Version -
   Mediatek ≫ Mt8188 Version -
   Mediatek ≫ Mt8195 Version -
   Mediatek ≫ Mt8395 Version -
   Mediatek ≫ Mt8673 Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.09% 0.007
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.4 0.8 3.6
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
CWE-125 Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

CWE-131 Incorrect Calculation of Buffer Size

The product does not correctly calculate the size to be used when allocating a buffer, which could lead to a buffer overflow.

https://corp.mediatek.com/product-security-bulletin/August-2023
Vendor Advisory