CVE-2022-20048

In video decoder, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05917502; Issue ID: ALPS05917502.
References
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:google:android:10.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:11.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:*
OR cpe:2.3:h:mediatek:mt5816:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt5835:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6885:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6893:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt9900:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt9901:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt9950:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt9969:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt9970:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt9980:-:*:*:*:*:*:*:*

History

17 Mar 2022, 17:29

Type Values Removed Values Added
First Time Mediatek mt5835
Mediatek mt5816
Mediatek mt9969
Mediatek mt6885
Mediatek mt9901
Mediatek mt9900
Mediatek mt9970
Google android
Mediatek mt9950
Mediatek mt9980
Mediatek
Google
Mediatek mt6893
CVSS v2 : unknown
v3 : unknown
v2 : 7.2
v3 : 7.8
References (MISC) https://corp.mediatek.com/product-security-bulletin/March-2022 - (MISC) https://corp.mediatek.com/product-security-bulletin/March-2022 - Vendor Advisory
CWE CWE-787
CPE cpe:2.3:h:mediatek:mt9970:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt5816:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt9901:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6885:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt9950:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt9900:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt9969:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt9980:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt5835:-:*:*:*:*:*:*:*
cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:10.0:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6893:-:*:*:*:*:*:*:*
cpe:2.3:o:google:android:11.0:*:*:*:*:*:*:*

10 Mar 2022, 17:54

Type Values Removed Values Added
New CVE

Information

Published : 2022-03-10 17:45

Updated : 2023-12-10 14:22


NVD link : CVE-2022-20048

Mitre link : CVE-2022-20048

CVE.ORG link : CVE-2022-20048


JSON object : View

Products Affected

mediatek

  • mt6893
  • mt9901
  • mt5816
  • mt9970
  • mt9969
  • mt9980
  • mt9900
  • mt6885
  • mt5835
  • mt9950

google

  • android
CWE
CWE-787

Out-of-bounds Write