CVE-2023-32826
02.10.2023, 03:15
In camera middleware, there is a possible out of bounds write due to a missing input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07993539; Issue ID: ALPS07993544.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| android | 12.0 | |
| android | 13.0 |
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| mediatek | mt6879 | 𝑥 ≤ * | ADP |
| mediatek | mt6886 | 𝑥 ≤ * | ADP |
| mediatek | mt6895 | 𝑥 ≤ * | ADP |
| mediatek | mt6983 | 𝑥 ≤ * | ADP |
| mediatek | mt6985 | 𝑥 ≤ * | ADP |
| mediatek | mt6989 | 𝑥 ≤ * | ADP |
| mediatek | mt8167 | 𝑥 ≤ * | ADP |
| mediatek | mt8167s | 𝑥 ≤ * | ADP |
| mediatek | mt8168 | 𝑥 ≤ * | ADP |
| mediatek | mt8173 | 𝑥 ≤ * | ADP |
| mediatek | mt8175 | 𝑥 ≤ * | ADP |
| mediatek | mt8185 | 𝑥 ≤ * | ADP |
| mediatek | mt8188 | 𝑥 ≤ * | ADP |
| mediatek | mt8195 | 𝑥 ≤ * | ADP |
| mediatek | mt8321 | 𝑥 ≤ * | ADP |
| mediatek | mt8362a | 𝑥 ≤ * | ADP |
| mediatek | mt8365 | 𝑥 ≤ * | ADP |
| mediatek | mt8385 | 𝑥 ≤ * | ADP |
| mediatek | mt8390 | 𝑥 ≤ * | ADP |
| mediatek | mt8395 | 𝑥 ≤ * | ADP |
| mediatek | mt8666 | 𝑥 ≤ * | ADP |
| mediatek | mt8673 | 𝑥 ≤ * | ADP |
| mediatek | mt8675 | 𝑥 ≤ * | ADP |
| mediatek | mt8765 | 𝑥 ≤ * | ADP |
| mediatek | mt8766 | 𝑥 ≤ * | ADP |
| mediatek | mt8768 | 𝑥 ≤ * | ADP |
| mediatek | mt8781 | 𝑥 ≤ * | ADP |
| mediatek | mt8786 | 𝑥 ≤ * | ADP |
| mediatek | mt8788 | 𝑥 ≤ * | ADP |
| mediatek | mt8789 | 𝑥 ≤ * | ADP |
| mediatek | mt8791 | 𝑥 ≤ * | ADP |
| mediatek | mt8791t | 𝑥 ≤ * | ADP |
| mediatek | mt8797 | 𝑥 ≤ * | ADP |
| mediatek | mt8798 | 𝑥 ≤ * | ADP |
Common Weakness Enumeration
- CWE-787 - Out-of-bounds WriteThe software writes data past the end, or before the beginning, of the intended buffer.
- CWE-20 - Improper Input ValidationThe product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.