CVE-2022-23747

In Sony Xperia series 1, 5, and Pro, an out of bound memory access can occur due to lack of validation of the number of frames being passed during music playback.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:sony:xperia_1_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:sony:xperia_1:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:sony:xperia_5_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:sony:xperia_5:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:sony:xperia_pro_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:sony:xperia_pro:-:*:*:*:*:*:*:*

History

19 Aug 2022, 15:01

Type Values Removed Values Added
CWE CWE-120
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CPE cpe:2.3:o:sony:xperia_5_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:sony:xperia_1:-:*:*:*:*:*:*:*
cpe:2.3:o:sony:xperia_pro_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:sony:xperia_pro:-:*:*:*:*:*:*:*
cpe:2.3:o:sony:xperia_1_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:sony:xperia_5:-:*:*:*:*:*:*:*
References (MISC) https://cpr-zero.checkpoint.com/vulns/cprid-2191/ - (MISC) https://cpr-zero.checkpoint.com/vulns/cprid-2191/ - Exploit, Third Party Advisory
References (MISC) https://research.checkpoint.com/2022/bad-alac-one-codec-to-hack-the-whole-world/ - (MISC) https://research.checkpoint.com/2022/bad-alac-one-codec-to-hack-the-whole-world/ - Exploit, Third Party Advisory

17 Aug 2022, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-08-17 21:15

Updated : 2024-02-04 22:51


NVD link : CVE-2022-23747

Mitre link : CVE-2022-23747

CVE.ORG link : CVE-2022-23747


JSON object : View

Products Affected

sony

  • xperia_pro_firmware
  • xperia_5_firmware
  • xperia_1
  • xperia_pro
  • xperia_1_firmware
  • xperia_5
CWE
CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')