CVE-2023-20798: Medium severity android vulnerability
Published Aug 7, 2023
·Updated
In pda, there is a possible out of bounds read due to an incorrect calculation of buffer size. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07147572; Issue ID: ALPS07421076.
Affected Software
13 affected components
Google Android=12.0
Google Android=13.0
MediaTek Mt2713
MediaTek Mt6855
MediaTek Mt6879
MediaTek Mt6886
MediaTek Mt6895
MediaTek Mt6983
MediaTek Mt6985
MediaTek Mt8188
MediaTek Mt8195
MediaTek Mt8395
MediaTek Mt8673
Event History
Aug 7, 2023
CVE Published
via MITRE·03:21 AM
Data Sourced
via MITRE·03:21 AM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2023-20798?
CVE-2023-20798 is a vulnerability in pda where there is a potential out-of-bounds read due to an incorrect calculation of buffer size.
2
What is the severity of CVE-2023-20798?
The severity of CVE-2023-20798 is medium with a CVSS score of 4.4.
3
What software versions are affected by CVE-2023-20798?
CVE-2023-20798 affects Google Android versions 12.0 and 13.0.
4
Is user interaction required for the exploitation of CVE-2023-20798?
No, user interaction is not needed for exploitation of CVE-2023-20798.
5
How can CVE-2023-20798 be fixed?
To fix CVE-2023-20798, apply the patch with ID ALPS07147572 or ALPS07421076.