PT-2023-20469 · Samsung · Exynos
Publicado
2023-03-13
·
Atualizado
2025-03-03
·
CVE-2023-26073
CVSS v3.1
7.6
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H |
Name of the Vulnerable Software and Affected Versions
Samsung Mobile Chipset and Baseband Modem Chipset for Exynos versions 850 through 2200
Samsung Mobile Chipset and Baseband Modem Chipset for Exynos Modem versions 5123 through 5300
Samsung Mobile Chipset and Baseband Modem Chipset for Exynos Auto version T5123
Samsung Mobile Chipset and Baseband Modem Chipset for Exynos W920 version
Description
A heap-based buffer overflow in the 5G MM message codec can occur due to insufficient parameter validation when decoding the extended emergency number list.
Recommendations
For Samsung Mobile Chipset and Baseband Modem Chipset for Exynos versions 850 through 2200, update to a version that includes a fix for the heap-based buffer overflow issue.
For Samsung Mobile Chipset and Baseband Modem Chipset for Exynos Modem versions 5123 through 5300, update to a version that includes a fix for the heap-based buffer overflow issue.
For Samsung Mobile Chipset and Baseband Modem Chipset for Exynos Auto version T5123, update to a version that includes a fix for the heap-based buffer overflow issue.
For Samsung Mobile Chipset and Baseband Modem Chipset for Exynos W920 version, update to a version that includes a fix for the heap-based buffer overflow issue.
As a temporary workaround, consider disabling the 5G MM message codec until a patch is available.
Exploit
Correção
Memory Corruption
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Exynos