CVE-2023-21282: High severity android vulnerability
Published Aug 7, 2023
·Updated
In TRANSPOSERSETTINGS of lpptran.h, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.
Affected Software
5 affected components
Google Android=11.0
Google Android=12.0
Google Android=12.1
Google Android=13.0
Google Android
Remediation
Patch Available
Event History
Aug 7, 2023
CVE Published
via Android·12:00 AM
Aug 14, 2023
CVE Published
via MITRE·09:05 PM
Data Sourced
via MITRE·09:05 PM
DescriptionWeakness
Data Sourced
via NVD·10:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-21282?
CVE-2023-21282 has been classified with a high severity level due to the potential for remote code execution.
2
How do I fix CVE-2023-21282?
To mitigate CVE-2023-21282, update your Android device to the latest available version provided by Google.
3
What are the affected versions for CVE-2023-21282?
CVE-2023-21282 affects Google Android versions 11.0, 12.0, 12.1, and 13.0.
4
Is user interaction required for CVE-2023-21282 exploitation?
Yes, user interaction is necessary for the exploitation of CVE-2023-21282.
5
What type of vulnerability is CVE-2023-21282?
CVE-2023-21282 is an out of bounds write vulnerability caused by an incorrect bounds check.