CVE-2023-20730: Medium severity yocto project vulnerability
Published Jun 6, 2023
·Updated
In wlan, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07573552; Issue ID: ALPS07573552.
Affected Software
20 affected components
All of the following
Any of the following
linuxfoundation Yocto=3.1
linuxfoundation Yocto=3.3
linuxfoundation Yocto=4.0
Google Android=13.0
Any of the following
MediaTek Mt6985
MediaTek Mt7902
MediaTek Mt7921
MediaTek Mt8365
MediaTek Mt8518
MediaTek Mt8532
linuxfoundation Yocto=3.1
linuxfoundation Yocto=3.3
linuxfoundation Yocto=4.0
Google Android=13.0
MediaTek Mt6985
MediaTek Mt7902
MediaTek Mt7921
MediaTek Mt8365
MediaTek Mt8518
MediaTek Mt8532
Event History
Jun 6, 2023
CVE Published
via MITRE·12:11 PM
Data Sourced
via MITRE·12:11 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2023-20730?
CVE-2023-20730 is a vulnerability in wlan that allows for a possible out of bounds read, leading to local information disclosure.
2
What is the severity of CVE-2023-20730?
CVE-2023-20730 has a severity score of 4.4, which is considered medium.
3
Which software versions are affected by CVE-2023-20730?
Linuxfoundation Yocto versions 3.1, 3.3, and 4.0, as well as Google Android 13.0, are affected by CVE-2023-20730.
4
Is Mediatek Mt6985 vulnerable to CVE-2023-20730?
No, Mediatek Mt6985 is not vulnerable to CVE-2023-20730.
5
How can I patch CVE-2023-20730?
To patch CVE-2023-20730, refer to the patch ID ALPS07573552 and follow the instructions provided.