CVE-2023-35673: Integer Overflow
Published Sep 5, 2023
·Updated
In buildreadmultirsp of gattsr.cc, there is a possible out of bounds write due to an integer overflow. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Software
5 affected components
Google Android=11.0
Google Android=12.0
Google Android=12.1
Google Android=13.0
Google Android
Event History
Sep 5, 2023
CVE Published
12:00 AM
Sep 11, 2023
CVE Published
via MITRE·08:09 PM
Data Sourced
via MITRE·08:09 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-35673?
The severity of CVE-2023-35673 is critical.
2
How can CVE-2023-35673 be exploited?
CVE-2023-35673 can be exploited remotely (proximal/adjacent) without requiring user interaction.
3
Which software is affected by CVE-2023-35673?
Google Android versions 11.0, 12.0, 12.1, and 13.0 are affected by CVE-2023-35673.
4
How can I fix CVE-2023-35673?
To fix CVE-2023-35673, apply the relevant security patches provided by Google for the affected Android versions.
5
What is the Common Weakness Enumeration (CWE) for CVE-2023-35673?
The CWE for CVE-2023-35673 is CWE-190 (Integer Overflow or Wraparound).