CVE-2023-20805: Medium severity yocto project vulnerability
Published Aug 7, 2023
·Updated
In imgsys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07199773; Issue ID: ALPS07326411.
Affected Software
22 affected components
All of the following
Any of the following
linuxfoundation Yocto=4.0
Google Android=12.0
Google Android=13.0
Any of the following
MediaTek Mt2713
MediaTek Mt6879
MediaTek Mt6895
MediaTek Mt6983
MediaTek Mt8188
MediaTek Mt8195
MediaTek Mt8395
MediaTek Mt8673
linuxfoundation Yocto=4.0
Google Android=12.0
Google Android=13.0
MediaTek Mt2713
MediaTek Mt6879
MediaTek Mt6895
MediaTek Mt6983
MediaTek Mt8188
MediaTek Mt8195
MediaTek Mt8395
MediaTek Mt8673
Event History
Aug 7, 2023
CVE Published
via MITRE·03:21 AM
Data Sourced
via MITRE·03:21 AM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2023-20805?
CVE-2023-20805 is a vulnerability in the imgsys software that could allow a local attacker to escalate privileges and execute arbitrary code.
2
What is the severity of CVE-2023-20805?
CVE-2023-20805 has a severity rating of medium (6.7).
3
How does CVE-2023-20805 impact Linuxfoundation Yocto?
Linuxfoundation Yocto version 4.0 is affected by CVE-2023-20805.
4
How does CVE-2023-20805 impact Google Android 12.0?
Google Android version 12.0 is affected by CVE-2023-20805.
5
How can I patch CVE-2023-20805?
To patch CVE-2023-20805, apply Patch ID ALPS07199773 or refer to the vendor's security bulletin for more information.