SB2023090402 - Multiple vulnerabilities in MediaTek chipsets



SB2023090402 - Multiple vulnerabilities in MediaTek chipsets

Published: September 4, 2023

Security Bulletin ID SB2023090402
Severity
Low
Patch available
YES
Number of vulnerabilities 45
Exploitation vector Local access
Highest impact Code execution

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 45 secuirty vulnerabilities.


1) Improper input validation (CVE-ID: CVE-2023-32807)

The vulnerability allows a local privileged application to execute arbitrary code.

The vulnerability exists due to improper input validation within connectivity system driver. A local privileged application can execute arbitrary code.


2) Improper input validation (CVE-ID: CVE-2023-20845)

The vulnerability allows a local privileged application to gain access to sensitive information.

The vulnerability exists due to a missing valid range checking within imgsys. A local privileged application can gain access to sensitive information.


3) Out-of-bounds read (CVE-ID: CVE-2023-20846)

The vulnerability allows a local privileged application to gain access to sensitive information.

The vulnerability exists due to a missing valid range checking within imgsys_cmdq. A local privileged application can gain access to sensitive information.


4) Improper input validation (CVE-ID: CVE-2023-20847)

The vulnerability allows a local privileged application to perform service disruption.

The vulnerability exists due to a missing valid range checking within imgsys_cmdq. A local privileged application can perform service disruption.


5) Improper input validation (CVE-ID: CVE-2023-20848)

The vulnerability allows a local privileged application to execute arbitrary code.

The vulnerability exists due to a missing valid range checking within imgsys_cmdq. A local privileged application can execute arbitrary code.


6) Use After Free (CVE-ID: CVE-2023-20849)

The vulnerability allows a local privileged application to execute arbitrary code.

The vulnerability exists due to a missing valid range checking within imgsys_cmdq. A local privileged application can execute arbitrary code.


7) Out-of-bounds write (CVE-ID: CVE-2023-20850)

The vulnerability allows a local privileged application to execute arbitrary code.

The vulnerability exists due to a missing valid range checking within imgsys_cmdq. A local privileged application can execute arbitrary code.


8) Out-of-bounds read (CVE-ID: CVE-2023-20851)

The vulnerability allows a local privileged application to execute arbitrary code.

The vulnerability exists due to a race condition within stc. A local privileged application can execute arbitrary code.


9) Out-of-bounds write (CVE-ID: CVE-2023-32805)

The vulnerability allows a local privileged application to execute arbitrary code.

The vulnerability exists due to an insecure default value within power. A local privileged application can execute arbitrary code.


10) Improper input validation (CVE-ID: CVE-2023-32806)

The vulnerability allows a local privileged application to execute arbitrary code.

The vulnerability exists due to improper input validation within wlan driver. A local privileged application can execute arbitrary code.


11) Improper Access Control for Register Interface (CVE-ID: CVE-2023-32808)

The vulnerability allows a local privileged application to execute arbitrary code.

The vulnerability exists due to improper access control of register interface within bluetooth driver. A local privileged application can execute arbitrary code.


12) Improper input validation (CVE-ID: CVE-2023-20843)

The vulnerability allows a local privileged application to gain access to sensitive information.

The vulnerability exists due to a missing valid range checking within imgsys_cmdq. A local privileged application can gain access to sensitive information.


13) Improper Access Control for Register Interface (CVE-ID: CVE-2023-32809)

The vulnerability allows a local privileged application to execute arbitrary code.

The vulnerability exists due to improper access control of register interface within bluetooth driver. A local privileged application can execute arbitrary code.


14) Improper input validation (CVE-ID: CVE-2023-32810)

The vulnerability allows a local privileged application to gain access to sensitive information.

The vulnerability exists due to improper input validation within bluetooth driver. A local privileged application can gain access to sensitive information.


15) Improper input validation (CVE-ID: CVE-2023-32811)

The vulnerability allows a local privileged application to execute arbitrary code.

The vulnerability exists due to improper input validation within connectivity system driver. A local privileged application can execute arbitrary code.


16) Improper input validation (CVE-ID: CVE-2023-32812)

The vulnerability allows a local privileged application to execute arbitrary code.

The vulnerability exists due to improper input validation within gnss service. A local privileged application can execute arbitrary code.


17) Improper input validation (CVE-ID: CVE-2023-32813)

The vulnerability allows a local privileged application to execute arbitrary code.

The vulnerability exists due to improper input validation within gnss service. A local privileged application can execute arbitrary code.


18) Improper input validation (CVE-ID: CVE-2023-32814)

The vulnerability allows a local privileged application to execute arbitrary code.

The vulnerability exists due to improper input validation within gnss service. A local privileged application can execute arbitrary code.


19) Improper input validation (CVE-ID: CVE-2023-32815)

The vulnerability allows a local privileged application to execute arbitrary code.

The vulnerability exists due to improper input validation within gnss service. A local privileged application can execute arbitrary code.


20) Improper input validation (CVE-ID: CVE-2023-32816)

The vulnerability allows a local privileged application to execute arbitrary code.

The vulnerability exists due to improper input validation within gnss service. A local privileged application can execute arbitrary code.


21) Improper input validation (CVE-ID: CVE-2023-32817)

The vulnerability allows a local privileged application to execute arbitrary code.

The vulnerability exists due to improper input validation within gnss service. A local privileged application can execute arbitrary code.


22) Out-of-bounds read (CVE-ID: CVE-2023-20844)

The vulnerability allows a local privileged application to gain access to sensitive information.

The vulnerability exists due to a missing valid range checking within imgsys_cmdq. A local privileged application can gain access to sensitive information.


23) Improper input validation (CVE-ID: CVE-2023-20842)

The vulnerability allows a local privileged application to execute arbitrary code.

The vulnerability exists due to a missing within imgsys_cmdq. A local privileged application can execute arbitrary code.


24) Improper input validation (CVE-ID: CVE-2023-20820)

The vulnerability allows a local privileged application to execute arbitrary code.

The vulnerability exists due to improper input validation within wlan service. A local privileged application can execute arbitrary code.


25) Improper input validation (CVE-ID: CVE-2023-20830)

The vulnerability allows a local privileged application to execute arbitrary code.

The vulnerability exists due to a missing bounds check within gps. A local privileged application can execute arbitrary code.


26) Improper input validation (CVE-ID: CVE-2023-20821)

The vulnerability allows a local privileged application to execute arbitrary code.

The vulnerability exists due to a missing bounds check within nvram. A local privileged application can execute arbitrary code.


27) Improper input validation (CVE-ID: CVE-2023-20822)

The vulnerability allows a local privileged application to execute arbitrary code.

The vulnerability exists due to a missing bounds check within netdagent. A local privileged application can execute arbitrary code.


28) Improper input validation (CVE-ID: CVE-2023-20823)

The vulnerability allows a local privileged application to perform service disruption.

The vulnerability exists due to an incorrect status check within cmdq. A local privileged application can perform service disruption.


29) Improper input validation (CVE-ID: CVE-2023-20824)

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to a missing permission check within duraspeed. A local application can gain access to sensitive information.


30) Improper input validation (CVE-ID: CVE-2023-20825)

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to a missing permission check within duraspeed. A local application can gain access to sensitive information.


31) Improper input validation (CVE-ID: CVE-2023-20826)

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to a missing permission check within cta. A local application can gain access to sensitive information.


32) Improper Synchronization (CVE-ID: CVE-2023-20827)

The vulnerability allows a local privileged application to execute arbitrary code.

The vulnerability exists due to a race condition within ims service. A local privileged application can execute arbitrary code.


33) Improper input validation (CVE-ID: CVE-2023-20828)

The vulnerability allows a local privileged application to execute arbitrary code.

The vulnerability exists due to a missing bounds check within gps. A local privileged application can execute arbitrary code.


34) Improper input validation (CVE-ID: CVE-2023-20829)

The vulnerability allows a local privileged application to execute arbitrary code.

The vulnerability exists due to a missing bounds check within gps. A local privileged application can execute arbitrary code.


35) Improper input validation (CVE-ID: CVE-2023-20831)

The vulnerability allows a local privileged application to execute arbitrary code.

The vulnerability exists due to a missing bounds check within gps. A local privileged application can execute arbitrary code.


36) Buffer overflow (CVE-ID: CVE-2023-20841)

The vulnerability allows a local privileged application to execute arbitrary code.

The vulnerability exists due to a missing valid range checking within imgsys. A local privileged application can execute arbitrary code.


37) Improper input validation (CVE-ID: CVE-2023-20832)

The vulnerability allows a local privileged application to execute arbitrary code.

The vulnerability exists due to a missing bounds check within gps. A local privileged application can execute arbitrary code.


38) Improper input validation (CVE-ID: CVE-2023-20833)

The vulnerability allows a local privileged application to gain access to sensitive information.

The vulnerability exists due to a missing bounds check within keyinstall. A local privileged application can gain access to sensitive information.


39) Use After Free (CVE-ID: CVE-2023-20834)

The vulnerability allows a local privileged application to execute arbitrary code.

The vulnerability exists due to a race condition within pda. A local privileged application can execute arbitrary code.


40) Use After Free (CVE-ID: CVE-2023-20835)

The vulnerability allows a local privileged application to execute arbitrary code.

The vulnerability exists due to a race condition within camsys. A local privileged application can execute arbitrary code.


41) Out-of-bounds read (CVE-ID: CVE-2023-20836)

The vulnerability allows a local privileged application to gain access to sensitive information.

The vulnerability exists due to a missing bounds check within camsys. A local privileged application can gain access to sensitive information.


42) Out-of-bounds write (CVE-ID: CVE-2023-20837)

The vulnerability allows a local privileged application to execute arbitrary code.

The vulnerability exists due to a missing bounds check within seninf. A local privileged application can execute arbitrary code.


43) Out-of-bounds read (CVE-ID: CVE-2023-20838)

The vulnerability allows a local privileged application to gain access to sensitive information.

The vulnerability exists due to a race condition within imgsys. A local privileged application can gain access to sensitive information.


44) Out-of-bounds read (CVE-ID: CVE-2023-20839)

The vulnerability allows a local privileged application to gain access to sensitive information.

The vulnerability exists due to a missing valid range checking within imgsys. A local privileged application can gain access to sensitive information.


45) Out-of-bounds write (CVE-ID: CVE-2023-20840)

The vulnerability allows a local privileged application to execute arbitrary code.

The vulnerability exists due to a missing valid range checking within imgsys. A local privileged application can execute arbitrary code.


Remediation

Install update from vendor's website.