CVE-2023-20790: Medium severity yocto project vulnerability
In nvram, there is a possible out of bounds write due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07740194; Issue ID: ALPS07740194.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-20790?
CVE-2023-20790 is a vulnerability in nvram that allows for a possible out of bounds write due to a missing bounds check.
What is the severity of CVE-2023-20790?
The severity of CVE-2023-20790 is medium with a severity value of 4.4.
Which software is affected by CVE-2023-20790?
The affected software includes Linuxfoundation Yocto versions 2.6 and 3.3, Rdkcentral Rdk-b version 2022q3, Google Android versions 12.0 and 13.0, and Openwrt versions 19.07.0 and 21.02.0.
Is user interaction needed for exploitation of CVE-2023-20790?
No, user interaction is not needed for exploitation of CVE-2023-20790.
How can CVE-2023-20790 be fixed?
To fix CVE-2023-20790, apply the patch with Patch ID ALPS07740194 or Issue ID ALPS07740194.