In typec, there is a possible out of bounds write due to an incorrect calculation of buffer size. This could lead to local escalation of privilege, for an attacker who has physical access to the device, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07262364; Issue ID: ALPS07262364.
References
Link | Resource |
---|---|
https://corp.mediatek.com/product-security-bulletin/November-2022 | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
History
09 Nov 2022, 16:07
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-131 | |
CPE | cpe:2.3:h:mediatek:mt6895:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt8798:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt6983:-:*:*:*:*:*:*:* cpe:2.3:o:google:android:11.0:*:*:*:*:*:*:* cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt6855:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt6789:-:*:*:*:*:*:*:* cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:* |
|
References | (MISC) https://corp.mediatek.com/product-security-bulletin/November-2022 - Vendor Advisory | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.8 |
08 Nov 2022, 21:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2022-11-08 21:15
Updated : 2024-02-04 22:51
NVD link : CVE-2022-32617
Mitre link : CVE-2022-32617
CVE.ORG link : CVE-2022-32617
JSON object : View
Products Affected
mediatek
- mt8798
- mt6855
- mt6895
- mt6789
- mt6983
- android
CWE
CWE-131
Incorrect Calculation of Buffer Size