CVE-2024-0023
published 2024-02-16CVE-2024-0023: In ConvertRGBToPlanarYUV of Codec2BufferUtils.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local…
PriorityP343high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.39%
31.3th percentile
In ConvertRGBToPlanarYUV of Codec2BufferUtils.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| platform | frameworks_av | >= 11:0 < 11:2024-01-01 | 11:2024-01-01 |
| platform | frameworks_av | >= 12:0 < 12:2024-01-01 | 12:2024-01-01 |
| platform | frameworks_av | >= 12L:0 < 12L:2024-01-01 | 12L:2024-01-01 |
| platform | frameworks_av | >= 13:0 < 13:2024-01-01 | 13:2024-01-01 |
| platform | frameworks_av | >= 14-next:0 < 14-next:2024-01-01 | 14-next:2024-01-01 |
| platform | frameworks_av | >= 14:0 < 14:2024-01-01 | 14:2024-01-01 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
cisa9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3x35-4hvx-j24p: In ConvertRGBToPlanarYUV of Codec2BufferUtils
ghsa_unreviewed·2024-02-16
CVE-2024-0023 [HIGH] CWE-787 GHSA-3x35-4hvx-j24p: In ConvertRGBToPlanarYUV of Codec2BufferUtils
In ConvertRGBToPlanarYUV of Codec2BufferUtils.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
OSV
CVE-2024-0023: In ConvertRGBToPlanarYUV of Codec2BufferUtils
osv·2024-01-01
CVE-2024-0023 CVE-2024-0023: In ConvertRGBToPlanarYUV of Codec2BufferUtils
In ConvertRGBToPlanarYUV of Codec2BufferUtils.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CISA
VMware vCenter Server Out-of-Bounds Write Vulnerability
cisa·2024-01-22·CVSS 9.8
CVE-2023-34048 [CRITICAL] CWE-787 VMware vCenter Server Out-of-Bounds Write Vulnerability
Vulnerability: VMware vCenter Server Out-of-Bounds Write Vulnerability
Affected: VMware vCenter Server
VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol that allows an attacker to conduct remote code execution.
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Notes: https://www.vmware.com/security/advisories/VMSA-2023-0023.html; https://nvd.nist.gov/vuln/detail/CVE-2023-34048
Remediation Due Date: 2024-02-12
Android
CVE-2024-0023: Android Security Bulletin 2024-01-01
CVE: CVE-2024-0023
Severity: HIGH
Type: EoP
Affected AOSP versions: 11, 12, 12L, 13, 14
References: A-283099444
[
vendor_android·2024-01-01·CVSS 7.8
CVE-2024-0023 [HIGH] CVE-2024-0023: Android Security Bulletin 2024-01-01
CVE: CVE-2024-0023
Severity: HIGH
Type: EoP
Affected AOSP versions: 11, 12, 12L, 13, 14
References: A-283099444
[
Android Security Bulletin 2024-01-01
CVE: CVE-2024-0023
Severity: HIGH
Type: EoP
Affected AOSP versions: 11, 12, 12L, 13, 14
References: A-283099444
[2]
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://android.googlesource.com/platform/frameworks/av/+/30b1b34cfd5abfcfee759e7d13167d368ac6c268https://source.android.com/security/bulletin/2024-01-01https://android.googlesource.com/platform/frameworks/av/+/30b1b34cfd5abfcfee759e7d13167d368ac6c268https://source.android.com/security/bulletin/2024-01-01
2024-02-16
Published