First published: Thu May 04 2023(Updated: )
Out-of-bounds Read vulnerability while processing BC_TUI_CMD_SEND_RESOURCE_DATA_ARRAY command in bc_tui trustlet from Samsung Blockchain Keystore prior to version 1.3.12.1 allows local attacker to read arbitrary memory.
Credit: mobile.security@samsung.com
Affected Software | Affected Version | How to fix |
---|---|---|
Samsung Samsung Blockchain Keystore | <1.3.12.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-21507 is the reference number for an Out-of-bounds Read vulnerability in Samsung Blockchain Keystore.
CVE-2023-21507 allows a local attacker to read arbitrary memory while processing a specific command in Samsung Blockchain Keystore prior to version 1.3.12.1.
CVE-2023-21507 has a severity rating of 5.5, which is considered medium.
If you are using Samsung Blockchain Keystore version 1.3.12.1 or earlier, your system is affected by CVE-2023-21507.
Yes, the fix for CVE-2023-21507 is to update Samsung Blockchain Keystore to version 1.3.12.1 or later.