In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08932916; Issue ID: MSV-1550.
History

Thu, 05 Sep 2024 14:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:*

Tue, 03 Sep 2024 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Mediatek
Mediatek mt6765
Mediatek mt6768
Mediatek mt6779
Mediatek mt6785
Mediatek mt8385
Mediatek mt8666
Mediatek mt8667
Mediatek mt8766
Mediatek mt8768
Mediatek mt8781
Mediatek mt8788
Mediatek mt8789
CPEs cpe:2.3:h:mediatek:mt6765:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6768:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6779:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6785:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8385:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8666:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8667:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8766:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8768:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8781:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8788:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8789:-:*:*:*:*:*:*:*
cpe:2.3:o:google:android:12.0:-:*:*:*:*:*:*
Vendors & Products Google
Google android
Mediatek
Mediatek mt6765
Mediatek mt6768
Mediatek mt6779
Mediatek mt6785
Mediatek mt8385
Mediatek mt8666
Mediatek mt8667
Mediatek mt8766
Mediatek mt8768
Mediatek mt8781
Mediatek mt8788
Mediatek mt8789
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 02 Sep 2024 02:30:00 +0000

Type Values Removed Values Added
Description In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08932916; Issue ID: MSV-1550.
Weaknesses CWE-787
References

cve-icon MITRE

Status: PUBLISHED

Assigner: MediaTek

Published: 2024-09-02T02:07:34.765Z

Updated: 2024-09-03T14:18:57.075Z

Reserved: 2023-11-02T13:35:35.173Z

Link: CVE-2024-20087

cve-icon Vulnrichment

Updated: 2024-09-03T14:17:03.867Z

cve-icon NVD

Status : Analyzed

Published: 2024-09-02T05:15:15.110

Modified: 2024-09-05T14:26:51.497

Link: CVE-2024-20087

cve-icon Redhat

No data.