PT-2021-7215 · Mediatek+1 · Mediatek Mt6735+4
Published
2021-12-01
·
Updated
2022-04-25
·
CVE-2021-0675
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Android SoC versions (affected versions not specified)
MediaTek MT6570 version (version not specified)
MediaTek MT6580 version (version not specified)
MediaTek MT6735 version (version not specified)
MediaTek MT6737 version (version not specified)
Description
The issue is related to an incorrect bounds check in the alac decoder, which could lead to a possible out of bounds write. This may result in local escalation of privilege without requiring additional execution privileges. User interaction is not necessary for exploitation. The problem is associated with buffer overflow in memory operations.
Recommendations
For Android SoC, apply the patch with ID: ALPS06064258 to resolve the issue.
For MediaTek MT6570, MT6580, MT6735, and MT6737, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Buffer Overflow
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Android
Mediatek Mt6570
Mediatek Mt6580
Mediatek Mt6735
Mediatek Mt6737