CVE-2023-21500Double Free in Mobile Devices

CWE-415Double Free3 documents3 sources
Severity
5.5MEDIUMNVD
CNA6.0
EPSS
0.0%
top 91.46%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 4

Description

Double free validation vulnerability in setPinPadImages in mPOS TUI trustlet prior to SMR May-2023 Release 1 allows local attackers to access the trustlet memory.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages2 packages

CVEListV5samsung_mobile/samsung_mobile_devicesSelect Android 13 devicesSMR May-2023 Release 1
NVDsamsung/android13.0

🔴Vulnerability Details

2
GHSA
GHSA-c256-xp72-rp74: Double free validation vulnerability in setPinPadImages in mPOS TUI trustlet prior to SMR May-2023 Release 1 allows local attackers to access the trus2023-05-04
CVEList
CVE-2023-21500: Double free validation vulnerability in setPinPadImages in mPOS TUI trustlet prior to SMR May-2023 Release 1 allows local attackers to access the trus2023-05-04
CVE-2023-21500 — Double Free in Samsung Mobile Devices | cvebase