Out of Bounds Write in imgsys Affects MediaTek Products
CVE-2023-20805
6.7MEDIUM
Key Information:
- Vendor
MediaTek
- Vendor
- CVE Published:
- 7 August 2023
What is CVE-2023-20805?
The imgsys component in MediaTek products has a significant vulnerability that allows for a potential out of bounds write. This issue arises from a missing bounds check within the system, enabling local escalation of privileges. Critical system execution privileges are necessary for exploitation, and notably, no user interaction is required to trigger this vulnerability. MediaTek has released a patch, identified as ALPS07199773, to mitigate this risk.
Affected Version(s)
MT2713, MT6879, MT6895, MT6983, MT8188, MT8195, MT8395, MT8673 Android 12.0, 13.0 / IOT-v23.0 (Yocto 4.0)