CVE-2023-20804: Medium severity yocto project vulnerability
Published Aug 7, 2023
·Updated
In imgsys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07199773; Issue ID: ALPS07326384.
Affected Software
22 affected components
All of the following
Any of the following
linuxfoundation Yocto=4.0
Google Android=12.0
Google Android=13.0
Any of the following
MediaTek Mt2713
MediaTek Mt6879
MediaTek Mt6895
MediaTek Mt6983
MediaTek Mt8188
MediaTek Mt8195
MediaTek Mt8395
MediaTek Mt8673
linuxfoundation Yocto=4.0
Google Android=12.0
Google Android=13.0
MediaTek Mt2713
MediaTek Mt6879
MediaTek Mt6895
MediaTek Mt6983
MediaTek Mt8188
MediaTek Mt8195
MediaTek Mt8395
MediaTek Mt8673
Event History
Aug 7, 2023
CVE Published
via MITRE·03:21 AM
Data Sourced
via MITRE·03:21 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-20804?
The severity of CVE-2023-20804 is medium.
2
What is the affected software for CVE-2023-20804?
The affected software for CVE-2023-20804 includes Linuxfoundation Yocto 4.0, Google Android 12.0, and Google Android 13.0.
3
Is Mediatek Mt2713 vulnerable to CVE-2023-20804?
No, Mediatek Mt2713 is not vulnerable to CVE-2023-20804.
4
Is there a patch available for CVE-2023-20804?
Yes, a patch ID ALPS07199773 is available for CVE-2023-20804.
5
Where can I find more information about CVE-2023-20804?
You can find more information about CVE-2023-20804 at https://corp.mediatek.com/product-security-bulletin/August-2023.