CVE-2023-20689: Integer Overflow
Published Jul 4, 2023
·Updated
In wlan firmware, there is possible system crash due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07664741; Issue ID: ALPS07664741.
Affected Software
10 affected components
linuxfoundation Yocto=4.0
Google Android=11.0
MediaTek Mt6739
MediaTek Mt8167
MediaTek Mt8321
MediaTek Mt8365
MediaTek Mt8385
MediaTek Mt8666
MediaTek Mt8765
MediaTek Mt8788
Event History
Jul 4, 2023
CVE Published
via MITRE·01:44 AM
Data Sourced
via MITRE·01:44 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-20689.
2
What is the severity level of CVE-2023-20689?
The severity level of CVE-2023-20689 is high, with a severity value of 7.5.
3
Which software is affected by CVE-2023-20689?
Linuxfoundation Yocto 4.0 and Google Android 11.0 are affected by CVE-2023-20689.
4
Is user interaction required for exploitation of CVE-2023-20689?
No, user interaction is not needed for exploitation of CVE-2023-20689.
5
How do I fix CVE-2023-20689?
To fix CVE-2023-20689, apply the patch identified as ALPS07664741.