CVE-2024-20049: Medium severity yocto project vulnerability
In flashc, there is a possible information disclosure due to an uncaught exception. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541765; Issue ID: ALPS08541765.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-20049?
CVE-2024-20049 is classified as a moderate severity vulnerability due to the potential for local information disclosure.
How do I fix CVE-2024-20049?
To fix CVE-2024-20049, you should apply the patch identified as ALPS08541765.
Which systems are affected by CVE-2024-20049?
CVE-2024-20049 affects specific versions of Yocto Project, RDK Central RDKB, and Android systems.
What kind of attack vector is associated with CVE-2024-20049?
CVE-2024-20049 can lead to local information disclosure and does not require user interaction.
What could be the potential impact of exploiting CVE-2024-20049?
Exploitation of CVE-2024-20049 could lead to unauthorized local access to sensitive information.