CVE-2023-20849

All FrameworksAndroidCWE-416CVE-2023-20849

CVE-2023-20849

State: PUBLISHED · Published: 2023-09-04 · Updated: 2024-10-01 · Assigner: MediaTek
Description
In imgsys_cmdq, there is a possible use after free due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07340433; Issue ID: ALPS07340350.
CWE
Affected
CVSS
References
Source
cvelistV5-main/cves/2023/20xxx/CVE-2023-20849.json