CVE-2023-20836: Medium severity android vulnerability
Published Sep 4, 2023
·Updated
In camsys, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07505629; Issue ID: ALPS07505629.
Affected Software
17 affected components
Google Android=11.0
Google Android=12.0
Google Android=13.0
MediaTek Mt6762
MediaTek Mt6765
MediaTek Mt6768
MediaTek Mt6771
MediaTek Mt6779
MediaTek Mt6781
MediaTek Mt6785
MediaTek Mt6833
MediaTek Mt6853
MediaTek Mt6877
MediaTek Mt6885
MediaTek Mt6893
MediaTek Mt8768
MediaTek Mt8788
Event History
Sep 4, 2023
CVE Published
via MITRE·02:27 AM
Data Sourced
via MITRE·02:27 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-20836.
2
What is the severity of CVE-2023-20836?
The severity of CVE-2023-20836 is medium with a severity value of 4.4.
3
Which software is affected by CVE-2023-20836?
The following software versions are affected by CVE-2023-20836: Google Android 11.0, Google Android 12.0, Google Android 13.0.
4
Is user interaction needed for exploitation of CVE-2023-20836?
No, user interaction is not needed for exploitation of CVE-2023-20836.
5
How can I fix CVE-2023-20836?
To fix CVE-2023-20836, apply the provided patch ID: ALPS07505629.