CVE-2023-40090
published 2023-12-04CVE-2023-40090: In BTM_BleVerifySignature of btm_ble.cc, there is a possible way to bypass signature validation due to side channel information disclosure. This could lead to…
PriorityP337medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
0.54%
41.9th percentile
In BTM_BleVerifySignature of btm_ble.cc, there is a possible way to bypass signature validation due to side channel information disclosure. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| platform | packages_modules_bluetooth | >= 13:0 < 13:2023-12-01 | 13:2023-12-01 |
| platform | packages_modules_bluetooth | >= 14:0 < 14:2023-12-01 | 14:2023-12-01 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
osv6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-x74m-v58j-5gpr: In BTM_BleVerifySignature of btm_ble
ghsa_unreviewed·2023-12-05
CVE-2023-40090 [MEDIUM] CWE-203 GHSA-x74m-v58j-5gpr: In BTM_BleVerifySignature of btm_ble
In BTM_BleVerifySignature of btm_ble.cc, there is a possible way to bypass signature validation due to side channel information disclosure. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
OSV
CVE-2023-40090: In BTM_BleVerifySignature of btm_ble
osv·2023-12-01
CVE-2023-40090 CVE-2023-40090: In BTM_BleVerifySignature of btm_ble
In BTM_BleVerifySignature of btm_ble.cc, there is a possible way to bypass signature validation due to side channel information disclosure. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
OSV
tiff vulnerabilities
osv·2023-11-23·CVSS 6.5
CVE-2022-40090 tiff vulnerabilities
tiff vulnerabilities
It was discovered that LibTIFF could be made to run into an infinite loop.
If a user or an automated system were tricked into opening a specially
crafted image file, an attacker could possibly use this issue to cause a
denial of service. (CVE-2022-40090)
It was discovered that LibTIFF could be made leak memory. If a user or an
automated system were tricked into opening a specially crafted image file,
an attacker could possibly use this issue to cause a denial of service.
(CVE-2023-3576)
Android
CVE-2023-40090: Android Security Bulletin 2023-12-01
CVE: CVE-2023-40090
Severity: HIGH
Type: EoP
Affected AOSP versions: 11, 12, 12L, 13, 14
References: A-274478807
vendor_android·2023-12-01·CVSS 6.5
CVE-2023-40090 [MEDIUM] CVE-2023-40090: Android Security Bulletin 2023-12-01
CVE: CVE-2023-40090
Severity: HIGH
Type: EoP
Affected AOSP versions: 11, 12, 12L, 13, 14
References: A-274478807
Android Security Bulletin 2023-12-01
CVE: CVE-2023-40090
Severity: HIGH
Type: EoP
Affected AOSP versions: 11, 12, 12L, 13, 14
References: A-274478807
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://android.googlesource.com/platform/packages/modules/Bluetooth/+/495417bd068c35de0729d9a332639bd0699153ffhttps://source.android.com/security/bulletin/2023-12-01https://android.googlesource.com/platform/packages/modules/Bluetooth/+/495417bd068c35de0729d9a332639bd0699153ffhttps://source.android.com/security/bulletin/2023-12-01
2023-12-04
Published