CVE-2024-20055: Medium severity yocto project vulnerability
Published Apr 1, 2024
·Updated
In imgsys, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation Patch ID: ALPS08518692; Issue ID: MSV-1012.
Affected Software
20 affected components
All of the following
Any of the following
linuxfoundation Yocto=4.0
MediaTek Iot Yocto=23.2
Google Android=12.0
Google Android=13.0
Any of the following
MediaTek Mt2713
MediaTek Mt8168
MediaTek Mt8173
MediaTek Mt8175
MediaTek Mt8188
MediaTek Mt8195
MediaTek Mt8365
MediaTek Mt8370
MediaTek Mt8390
MediaTek Mt8395
MediaTek Mt8673
MediaTek Mt8696
MediaTek Mt8781
MediaTek Mt8795t
MediaTek Mt8798
MediaTek Mt8871
Event History
Apr 1, 2024
CVE Published
via MITRE·02:35 AM
Data Sourced
via MITRE·02:35 AM
DescriptionWeakness
Data Sourced
via NVD·03:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-20055?
CVE-2024-20055 has a medium severity rating due to its potential for local information disclosure.
2
How do I fix CVE-2024-20055?
To fix CVE-2024-20055, apply the patch identified by Patch ID: ALPS08518692.
3
What software is affected by CVE-2024-20055?
CVE-2024-20055 affects Yocto Project version 4.0, MediaTek IoT Yocto version 23.2, and Android versions 12.0 and 13.0.
4
What are the potential risks of CVE-2024-20055?
Exploitation of CVE-2024-20055 could lead to unauthorized local information disclosure on vulnerable systems.
5
Is user interaction required to exploit CVE-2024-20055?
Yes, user interaction is needed for the exploitation of CVE-2024-20055.