CVE-2023-20966: Buffer Overflow
In inflate of inflate.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-242299736
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-20966?
CVE-2023-20966 has a critical severity level as it allows for local escalation of privilege due to a heap buffer overflow.
How do I fix CVE-2023-20966?
To fix CVE-2023-20966, ensure that your Android device is updated to the latest version provided by Google.
What versions of Android are affected by CVE-2023-20966?
CVE-2023-20966 affects Android versions 11.0, 12.0, 12.1, and 13.0.
Is user interaction required for the exploitation of CVE-2023-20966?
No, user interaction is not needed for the exploitation of CVE-2023-20966.
What is the potential impact of exploiting CVE-2023-20966?
Exploiting CVE-2023-20966 could lead to unauthorized escalation of privileges on an affected Android device.