In widevine, there is a possible out of bounds write due to a logic error. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07643304; Issue ID: ALPS07643304.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Google
Subscribe
|
Android
Subscribe
|
|
Mediatek
Subscribe
|
Mt6762
Subscribe
Mt6765
Subscribe
Mt6768
Subscribe
Mt6769
Subscribe
Mt6779
Subscribe
Mt6781
Subscribe
Mt6785
Subscribe
Mt6789
Subscribe
Mt6833
Subscribe
Mt6853
Subscribe
Mt6853t
Subscribe
Mt6855
Subscribe
Mt6873
Subscribe
Mt6875
Subscribe
Mt6877
Subscribe
Mt6879
Subscribe
Mt6883
Subscribe
Mt6885
Subscribe
Mt6889
Subscribe
Mt6891
Subscribe
Mt6893
Subscribe
Mt8195
Subscribe
Mt8768
Subscribe
Mt8786
Subscribe
Mt8788
Subscribe
Mt8789
Subscribe
Mt8797
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-24879 | In widevine, there is a possible out of bounds write due to a logic error. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07643304; Issue ID: ALPS07643304. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://corp.mediatek.com/product-security-bulletin/May-2023 |
|
History
Thu, 23 Jan 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: MediaTek
Published:
Updated: 2025-01-23T21:18:26.789Z
Reserved: 2022-10-28T00:00:00.000Z
Link: CVE-2023-20700
Updated: 2024-08-02T09:14:40.156Z
Status : Modified
Published: 2023-05-15T22:15:10.743
Modified: 2025-01-23T22:15:11.560
Link: CVE-2023-20700
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD