Buffer Overflow Vulnerability in MediaTek Products
CVE-2023-32859
Key Information:
- Vendor
- MediaTek
- Vendor
- CVE Published:
- 4 December 2023
Summary
A buffer overflow vulnerability exists in the MediaTek product line due to a missing bounds check in meta processing. This flaw could allow an attacker to escalate privileges locally, gaining System execution privileges without requiring user interaction. Users are encouraged to apply the patch identified as ALPS08000473 to mitigate the risks associated with this vulnerability.
Affected Version(s)
MT6761, MT6765, MT6768, MT6779, MT6781, MT6785, MT6789, MT6833, MT6835, MT6853, MT6855, MT6873, MT6877, MT6879, MT6883, MT6885, MT6886, MT6889, MT6893, MT6895, MT6983, MT6985, MT8167, MT8167S, MT8168, MT8173, MT8175, MT8185, MT8188, MT8188T, MT8195, MT8321, MT8362A, MT8365, MT8390, MT8395, MT8666, MT8675, MT8766, MT8768, MT8786, MT8788, MT8789, MT8797 Android 12.0, 13.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved