CVE-2024-20112: Medium severity android vulnerability
Published Nov 4, 2024
·Updated
In isp, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09071481; Issue ID: MSV-1730.
Affected Software
7 affected components
All of the following
Any of the following
Google Android=13.0
Google Android=14.0
Any of the following
MediaTek Mt6878
MediaTek Mt6886
MediaTek Mt6897
MediaTek Mt6985
MediaTek Mt8676
Event History
Nov 4, 2024
CVE Published
via MITRE·01:48 AM
Data Sourced
via MITRE·01:48 AM
DescriptionWeakness
Data Sourced
via NVD·02:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-20112?
CVE-2024-20112 is classified as a local denial of service vulnerability requiring system execution privileges and user interaction.
2
How do I fix CVE-2024-20112?
To mitigate CVE-2024-20112, apply the patch identified as ALPS09071481 to affected systems.
3
Which software versions are affected by CVE-2024-20112?
CVE-2024-20112 affects Android versions 13.0 and 14.0.
4
What are the potential consequences of exploiting CVE-2024-20112?
Exploitation of CVE-2024-20112 can result in a local denial of service.
5
Is user interaction required to exploit CVE-2024-20112?
Yes, user interaction is necessary for exploiting CVE-2024-20112.