CVE-2023-20845: Medium severity yocto project vulnerability
In imgsys, there is a possible out of bounds read due to a missing valid range checking. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07197795; Issue ID: ALPS07340357.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-20845?
CVE-2023-20845 is a vulnerability in imgsys that allows for a possible out-of-bounds read, leading to local information disclosure.
What is the severity of CVE-2023-20845?
The severity of CVE-2023-20845 is medium with a CVSSv3 score of 4.2.
Which software versions are affected by CVE-2023-20845?
Linuxfoundation Yocto 4.0, Mediatek Iot Yocto 23.0, Google Android 11.0 and 12.0, and Linux Kernel 6.1 are affected by CVE-2023-20845.
How can CVE-2023-20845 be exploited?
CVE-2023-20845 requires user interaction for exploitation.
Is there a patch available for CVE-2023-20845?
Yes, a patch with Patch ID ALPS07197795 and Issue ID ALPS07340357 is available for CVE-2023-20845.