CVE-2023-20734: Medium severity yocto project vulnerability
In vcu, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07645149; Issue ID: ALPS07645184.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-20734?
CVE-2023-20734 is a vulnerability in vcu that allows for a possible out of bounds write, leading to local escalation of privilege with System execution privileges.
How severe is CVE-2023-20734?
CVE-2023-20734 has a severity score of 6.7, which is considered medium.
Is user interaction needed to exploit CVE-2023-20734?
No, user interaction is not needed for exploitation of CVE-2023-20734.
How can I fix CVE-2023-20734?
To fix CVE-2023-20734, apply the patch identified by Patch ID: ALPS07645149 or Issue ID: ALPS07645184.
Where can I find more information about CVE-2023-20734?
More information about CVE-2023-20734 can be found at the following reference: [https://corp.mediatek.com/product-security-bulletin/June-2023]