In isp, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07162155; Issue ID: ALPS07162155.
References
Link | Resource |
---|---|
https://corp.mediatek.com/product-security-bulletin/May-2023 | Vendor Advisory |
https://corp.mediatek.com/product-security-bulletin/May-2023 | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
History
24 Jan 2025, 15:15
Type | Values Removed | Values Added |
---|---|---|
References | () https://corp.mediatek.com/product-security-bulletin/May-2023 - Vendor Advisory |
22 May 2023, 17:44
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:o:yoctoproject:yocto:4.0:*:*:*:*:*:*:* cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt6983:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt8673:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt6895:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt8395:-:*:*:*:*:*:*:* cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt8195:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt6879:-:*:*:*:*:*:*:* |
|
CWE | CWE-20 | |
First Time |
Mediatek mt8195
Mediatek mt8395 Mediatek mt6879 Yoctoproject Mediatek Mediatek mt6983 Mediatek mt8673 Yoctoproject yocto Mediatek mt6895 Google android |
|
References | (MISC) https://corp.mediatek.com/product-security-bulletin/May-2023 - Vendor Advisory | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.7 |
15 May 2023, 22:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-05-15 22:15
Updated : 2025-01-24 15:15
NVD link : CVE-2023-20721
Mitre link : CVE-2023-20721
JSON object : View
Products Affected
mediatek
- mt6879
- mt8395
- mt6895
- mt6983
- mt8673
- mt8195
yoctoproject
- yocto
- android
CWE
CWE-20
Improper Input Validation