First published: Mon Oct 02 2023(Updated: )
In vpu, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07767817; Issue ID: ALPS07767817.
Credit: security@mediatek.com security@mediatek.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mediatek Iot Yocto | =23.0 | |
Google Android | =12.0 | |
Mediatek Mt6771 | ||
Mediatek Mt6779 | ||
Mediatek Mt6785 | ||
Mediatek Mt6853 | ||
Mediatek Mt6853t | ||
Mediatek Mt6873 | ||
Mediatek Mt6877 | ||
Mediatek Mt6885 | ||
Mediatek Mt6891 | ||
Mediatek Mt6893 | ||
Mediatek Mt8183 | ||
Mediatek Mt8188 | ||
Mediatek Mt8195 | ||
Mediatek Mt8390 | ||
Mediatek Mt8395 | ||
All of | ||
Any of | ||
Mediatek Iot Yocto | =23.0 | |
Google Android | =12.0 | |
Any of | ||
Mediatek Mt6771 | ||
Mediatek Mt6779 | ||
Mediatek Mt6785 | ||
Mediatek Mt6853 | ||
Mediatek Mt6853t | ||
Mediatek Mt6873 | ||
Mediatek Mt6877 | ||
Mediatek Mt6885 | ||
Mediatek Mt6891 | ||
Mediatek Mt6893 | ||
Mediatek Mt8183 | ||
Mediatek Mt8188 | ||
Mediatek Mt8195 | ||
Mediatek Mt8390 | ||
Mediatek Mt8395 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-32828.
The severity of CVE-2023-32828 is medium with a CVSS score of 6.7.
The affected software for CVE-2023-32828 includes Mediatek Iot Yocto 23.0 and Google Android 12.0.
This vulnerability can be exploited locally with system execution privileges and does not require user interaction.
Yes, there is a patch available. Patch ID: ALPS07767817; Issue ID: ALPS07767817.