PT-2024-18544 · Mediatek+1 · Mt6765+25

Published

2024-05-06

·

Updated

2024-07-03

·

CVE-2024-20058

CVSS v3.1

4.4

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions No specific software name or affected versions are mentioned in the provided descriptions.
Description The issue is related to a possible out of bounds read in the keyInstall function due to a missing bounds check. This could lead to local information disclosure, requiring System execution privileges for exploitation. No user interaction is needed for exploitation.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Out of bounds Read

Weakness Enumeration

Related Identifiers

CVE-2024-20058

Affected Products

Mt6765
Android
Mt6768
Mt6785
Mt6833
Mt6853
Mt6855
Mt6893
Mt6983
Mt8321
Mt8385
Mt8755
Mt8765
Mt8766
Mt8768
Mt8771
Mt8781
Mt8786
Mt8788
Mt8789
Mt8791T
Mt8792
Mt8795T
Mt8796
Mt8797
Mt8798