PT-2021-7215 · Mediatek+1 · Mediatek Mt6735+4

Published

2021-12-01

·

Updated

2022-04-25

·

CVE-2021-0675

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Android SoC versions (affected versions not specified) MediaTek MT6570 version (version not specified) MediaTek MT6580 version (version not specified) MediaTek MT6735 version (version not specified) MediaTek MT6737 version (version not specified)
Description The issue is related to an incorrect bounds check in the alac decoder, which could lead to a possible out of bounds write. This may result in local escalation of privilege without requiring additional execution privileges. User interaction is not necessary for exploitation. The problem is associated with buffer overflow in memory operations.
Recommendations For Android SoC, apply the patch with ID: ALPS06064258 to resolve the issue. For MediaTek MT6570, MT6580, MT6735, and MT6737, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Buffer Overflow

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ASB-A-201895896
BDU:2022-03869
CVE-2021-0675
M-ALPS06064258

Affected Products

Android
Mediatek Mt6570
Mediatek Mt6580
Mediatek Mt6735
Mediatek Mt6737