← Back

CVE-2024-20011

nvd nist
Published: Feb 5, 2024Modified: Jun 20, 2025

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

In alac decoder, there is a possible information disclosure due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08441146; Issue ID: ALPS08441146.

Affected (3)

Products: Google: Android
1 product
Android
Configuration A
3 vulnerable · 17 platform
Vulnerable SoftwareAffected Versions
Google
Version 11.0
Version 12.0
Version 13.0
Running on/withPlatform Versions
Mediatek
Mt6985
All versions
Mediatek
Mt8127
All versions
Mediatek
Mt8135
All versions
Mediatek
Mt8167
All versions
Mediatek
Mt8167s
All versions
Mediatek
Mt8168
All versions
Mediatek
Mt8173
All versions
Mediatek
Mt8175
All versions
Mediatek
Mt8176
All versions
Mediatek
Mt8183
All versions
Mediatek
Mt8185
All versions
Mediatek
Mt8188
All versions
Mediatek
Mt8188t
All versions
Mediatek
Mt8195
All versions
Mediatek
Mt8195z
All versions
Mediatek
Mt8312c
All versions
Mediatek
Mt8312d
All versions

References (2)

Source: security@mediatek.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.