Vulnerability

CVE-2024-20009

In alac decoder, there is a possible out of bounds write due to an incorrect error handling. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS08441150; Issue ID: ALPS08441150.

Impact

Severity (Manufact.)

HIGH

Severity (NIST)

8.8

Severity (Android)

N/A

Chipsets

74

Devices

1207

Affected Hardware

NameAlso known asManufacturer
MT6580
MediaTek
MT6739
MediaTek
MT6761V/WE
Helio A20
MediaTek
MT6761V/WAB
Helio A22
MediaTek
MT6761V/WBB
Helio A22
MediaTek
MT6762V/WB
Helio A25
MediaTek
MT6762V/WD
Helio A25
MediaTek
MT6762
Helio P22
MediaTek
MT6765
Helio P35
MediaTek
MT6779V/CU
Helio P90
MediaTek
74 of 74 row(s) shown.

Rows per page

Page 1 of 8

Timeline

Introduced (est):
Jan 1, 2015
Reported:
Unknown
Advisory Published:
Feb 5, 2024
CVE Published:
Feb 5, 2024
Android Patch Level:
Feb 2024
For more information and a detailed analysis of the data presented on this website, please see our paper, to be presented at NDSS'25.
Follow us on Twitter