Memory Corruption Issue in imgsys by MediaTek
CVE-2023-20803

6.5MEDIUM

Key Information:

Summary

In the imgsys component provided by MediaTek, a potential memory corruption vulnerability has been identified due to improper input validation. This flaw could allow an attacker to gain local escalation of privileges, requiring system execution rights. Exploitation of this vulnerability necessitates user interaction, making it vital for users to remain vigilant. A patch has been released to address this impact, detailed in the corresponding security bulletin.

Affected Version(s)

MT2713, MT6879, MT6895, MT6983, MT8188, MT8195, MT8395, MT8673 Android 12.0, 13.0 / IOT-v23.0 (Yocto 4.0)

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.