Out of Bounds Read and Write Vulnerability in imgsys by MediaTek
CVE-2023-20840

6.5MEDIUM

Key Information:

Vendor
MediaTek
Vendor
CVE Published:
4 September 2023

Summary

The imgsys component by MediaTek is vulnerable to out of bounds read and write issues due to a failure in range validation. This vulnerability allows an attacker, with user interaction, to exploit the flaw potentially leading to local escalation of privileges. It is crucial for users to apply the latest patches to mitigate any risks associated with this vulnerability.

Affected Version(s)

MT6895, MT6897, MT6983, MT8188, MT8195, MT8395 Android 11.0, 12.0 / Linux 6.1 / IOT-v23.0 / Yocto 4.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.