CVE-2023-20936
published 2023-03-24CVE-2023-20936: In bta_av_rc_disc_done of bta_av_act.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of…
PriorityP340high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.10%
0.8th percentile
In bta_av_rc_disc_done of bta_av_act.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-226927612
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| platform | packages_modules_bluetooth | >= 13-next:0 < 13-next:2023-03-01 | 13-next:2023-03-01 |
| platform | packages_modules_bluetooth | >= 13:0 < 13:2023-03-01 | 13:2023-03-01 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_redhat8.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5mhh-jgxp-w9p8: In bta_av_rc_disc_done of bta_av_act
ghsa_unreviewed·2023-03-24
CVE-2023-20936 [HIGH] CWE-787 GHSA-5mhh-jgxp-w9p8: In bta_av_rc_disc_done of bta_av_act
In bta_av_rc_disc_done of bta_av_act.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-226927612
OSV
CVE-2023-20936: In bta_av_rc_disc_done of bta_av_act
osv·2023-03-01
CVE-2023-20936 CVE-2023-20936: In bta_av_rc_disc_done of bta_av_act
In bta_av_rc_disc_done of bta_av_act.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Red Hat
bluez: phone book access profile heap-based buffer overflow remote code execution vulnerability
vendor_redhat·2024-05-03·CVSS 8.0
CVE-2023-50229 [HIGH] CWE-122 bluez: phone book access profile heap-based buffer overflow remote code execution vulnerability
bluez: phone book access profile heap-based buffer overflow remote code execution vulnerability
BlueZ Phone Book Access Profile Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of BlueZ. User interaction is required to exploit this vulnerability in that the target must connect to a malicious Bluetooth device.
The specific flaw exists within the handling of the Phone Book Access profile. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-20936.
A flaw was found within the handling of
Android
CVE-2023-20936: Android Security Bulletin 2023-03-01
CVE: CVE-2023-20936
Severity: HIGH
Type: EoP
Affected AOSP versions: 11, 12, 12L, 13
References: A-226927612
vendor_android·2023-03-01·CVSS 7.8
CVE-2023-20936 [HIGH] CVE-2023-20936: Android Security Bulletin 2023-03-01
CVE: CVE-2023-20936
Severity: HIGH
Type: EoP
Affected AOSP versions: 11, 12, 12L, 13
References: A-226927612
Android Security Bulletin 2023-03-01
CVE: CVE-2023-20936
Severity: HIGH
Type: EoP
Affected AOSP versions: 11, 12, 12L, 13
References: A-226927612
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-03-24
Published