« List of all CVEs

CVE-2023-20845

Published: 9/4/2023 Last updated: 10/8/2024 Reserved: 10/28/2022

In imgsys, there is a possible out of bounds read due to a missing valid range checking. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07197795; Issue ID: ALPS07340357.

CNA assigner: MediaTek (ee979b05-11f8-4f25-a7e0-a1fa9c190374) Requested by: n/a

Opam packages affected (29)

albatross cdrom conf-bpftool conf-libbpf conf-linux-libc-dev core core_unix hvsock mirage-block-unix mm ocaml-probes ortools_solvers orun rawlink rawlink-eio rawlink-lwt restricted shell solo5 solo5-bindings-hvt solo5-bindings-spt solo5-cross-aarch64 solo5-kernel-ukvm tracy-client tuntap uring vhd-format vhd-format-lwt xapi-stdext-unix

Products affected (1)

Product Vendor Version
MT6895, MT6897, MT6983, MT8188, MT8195, MT8395 MediaTek, Inc. All versions < V4.6.0

References (2)