Out-of-bounds read in MediaTek products - CVE-2021-0411

 

Out-of-bounds read in MediaTek products - CVE-2021-0411

Published: March 7, 2023


Vulnerability identifier: #VU72948
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-0411
CWE-ID: CWE-125
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to an integer overflow within flv extractor. A local application can gain access to sensitive information.


Affected software

MT8768
MT9288
MT9286
MT9285
MT9256
MT8791
MT8789
MT8788
MT8786
MT9629
MT8766
MT8765
MT8735B
MT8735A
MT8385
MT8365
MT8362A
MT8321
MT8195
MT9670
MT9981
MT9980
MT9970
MT9950
MT9931
MT9688
MT9686
MT9685
MT9675
MT8185
MT9669
MT9652
MT9650
MT9639
MT9638
MT9636
MT9632
MT9631
MT6753
MT6765
MT6763
MT6762
MT6761
MT6757CH
MT6757CD
MT6757C
MT6757
MT6755S
MT6768
MT6750S
MT6739
MT6737
MT6735
MT6580
MT5599
MT5598
MT5597
MT5527
MT8183
MT8175
MT8173
MT8168
MT8167S
MT8167
MT8163
MT6895
MT5522
MT6833
MT6771
MT8797
MT6885
MT6889
MT6877
MT6873
MT6853T
MT6853
MT6785
MT6779

How to mitigate CVE-2021-0411

Install security update from vendor's website.


External References

Related Security Bulletins