CVE-2024-20011: Buffer Overflow
In alac decoder, there is a possible information disclosure due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08441146; Issue ID: ALPS08441146.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch ALPS08441146
Event History
Frequently Asked Questions
What is the severity of CVE-2024-20011?
CVE-2024-20011 has a high severity due to its potential to cause remote code execution.
How do I fix CVE-2024-20011?
To fix CVE-2024-20011, apply the security patch ALPS08441146 from the manufacturer.
Which versions of Android are affected by CVE-2024-20011?
CVE-2024-20011 affects Android versions 11.0, 12.0, and 13.0.
What are the risks associated with CVE-2024-20011?
The risks include potential remote code execution with no additional execution privileges required.
Is user interaction needed for CVE-2024-20011 exploitation?
No, user interaction is not needed for the exploitation of CVE-2024-20011.