CVE-2023-20839: Medium severity yocto project vulnerability
Published Sep 4, 2023
·Updated
In imgsys, there is a possible out of bounds read due to a missing valid range checking. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07326455; Issue ID: ALPS07326409.
Affected Software
13 affected components
linuxfoundation Yocto=4.0
MediaTek Iot Yocto=23.0
Google Android=11.0
Google Android=12.0
Linux Linux kernel=6.1
MediaTek Mt2713
MediaTek Mt6895
MediaTek Mt6897
MediaTek Mt6983
MediaTek Mt8188
MediaTek Mt8195
MediaTek Mt8395
MediaTek Mt8673
Event History
Sep 4, 2023
CVE Published
via MITRE·02:27 AM
Data Sourced
via MITRE·02:27 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-20839?
The severity of CVE-2023-20839 is medium (4.2).
2
What software is affected by CVE-2023-20839?
The affected software includes Linuxfoundation Yocto 4.0, Mediatek Iot Yocto 23.0, Google Android 11.0 and 12.0, and Linux Linux Kernel 6.1.
3
How can the vulnerability CVE-2023-20839 be exploited?
Exploiting CVE-2023-20839 requires user interaction.
4
Is there a patch available for CVE-2023-20839?
Yes, the patch ID is ALPS07326455 and the issue ID is ALPS07326409.
5
Where can I find more information about CVE-2023-20839?
More information about CVE-2023-20839 can be found at https://corp.mediatek.com/product-security-bulletin/September-2023.