CVE-2022-32618

In typec, there is a possible out of bounds write due to an incorrect calculation of buffer size. This could lead to local escalation of privilege, for an attacker who has physical access to the device, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07262454; Issue ID: ALPS07262454.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:google:android:11.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:*
OR cpe:2.3:h:mediatek:mt6833:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6873:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6893:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8798:-:*:*:*:*:*:*:*

History

09 Nov 2022, 17:03

Type Values Removed Values Added
CWE CWE-131
CPE cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6873:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6833:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6893:-:*:*:*:*:*:*:*
cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8798:-:*:*:*:*:*:*:*
cpe:2.3:o:google:android:11.0:*:*:*:*:*:*:*
References (MISC) https://corp.mediatek.com/product-security-bulletin/November-2022 - (MISC) https://corp.mediatek.com/product-security-bulletin/November-2022 - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.8

08 Nov 2022, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-11-08 21:15

Updated : 2024-02-04 22:51


NVD link : CVE-2022-32618

Mitre link : CVE-2022-32618

CVE.ORG link : CVE-2022-32618


JSON object : View

Products Affected

mediatek

  • mt6833
  • mt8798
  • mt6893
  • mt6873

google

  • android
CWE
CWE-131

Incorrect Calculation of Buffer Size