PT-2023-5119 · Google · Android

Published

2023-03-24

·

Updated

2023-03-29

·

CVE-2023-21013

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Android versions Android-13
Description The issue is related to a buffer overflow read in the hostapd.cpp component of the Android operating system. This could lead to local information disclosure with System execution privileges needed, and user interaction is not required for exploitation.
Recommendations For Android version Android-13, consider restricting access to the hostapd.cpp component until a patch is available. As a temporary workaround, disabling the forceStaDisconnection function in hostapd.cpp may help minimize the risk of exploitation.

Fix

Out of bounds Read

Weakness Enumeration

Related Identifiers

BDU:2023-05708
CVE-2023-21013

Affected Products

Android