CVE-2023-20803: Input Validation
Published Aug 7, 2023
·Updated
In imgsys, there is a possible memory corruption due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07326455; Issue ID: ALPS07326374.
Affected Software
22 affected components
All of the following
Any of the following
linuxfoundation Yocto=4.0
Google Android=12.0
Google Android=13.0
Any of the following
MediaTek Mt2713
MediaTek Mt6879
MediaTek Mt6895
MediaTek Mt6983
MediaTek Mt8188
MediaTek Mt8195
MediaTek Mt8395
MediaTek Mt8673
linuxfoundation Yocto=4.0
Google Android=12.0
Google Android=13.0
MediaTek Mt2713
MediaTek Mt6879
MediaTek Mt6895
MediaTek Mt6983
MediaTek Mt8188
MediaTek Mt8195
MediaTek Mt8395
MediaTek Mt8673
Event History
Aug 7, 2023
CVE Published
via MITRE·03:21 AM
Data Sourced
via MITRE·03:21 AM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2023-20803?
CVE-2023-20803 is a vulnerability in imgsys where there is a possible memory corruption due to improper input validation.
2
What are the affected software versions?
The affected software versions include Linuxfoundation Yocto 4.0, Google Android 12.0, and Google Android 13.0.
3
What is the severity of CVE-2023-20803?
CVE-2023-20803 has a severity rating of medium, with a CVSS score of 6.5.
4
What is the patch for CVE-2023-20803?
The patch for CVE-2023-20803 is ALPS07326455.
5
Is user interaction needed for exploitation?
Yes, user interaction is needed for exploitation of CVE-2023-20803.