CVE-2024-20078
July 1, 2024, 12:37 p.m.
Tags
Product(s) Impacted
venc
Description
In venc, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08737250; Issue ID: MSV-1452.
Weaknesses
CWE-843
Access of Resource Using Incompatible Type ('Type Confusion')
The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.
CWE ID: 843Date
Published: July 1, 2024, 5:15 a.m.
Last Modified: July 1, 2024, 12:37 p.m.
Status : Awaiting Analysis
CVE has been recently published to the CVE List and has been received by the NVD.
More infoSource
security@mediatek.com
References
security@mediatek.com