UNIX symbolic link following in MediaTek products - CVE-2022-21770
Published: July 8, 2022
Vulnerability identifier: #VU65038
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-21770
CWE-ID: CWE-61
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to a symlink following issue. A local application can use a specially crafted symbolic link to a critical file on the system and gain access to sensitive information.
Affected software
MT6781
MT6877
MT6893
MT8797
MT6879
MT6895
MT6983
MT8791
MT8798
MT6877
MT6893
MT8797
MT6879
MT6895
MT6983
MT8791
MT8798
How to mitigate CVE-2022-21770
Install updates from vendor's website.