SB2023100252 - Multiple vulnerabilities in Unisoc chipsets



SB2023100252 - Multiple vulnerabilities in Unisoc chipsets

Published: October 2, 2023

Security Bulletin ID SB2023100252
Severity
Medium
Patch available
YES
Number of vulnerabilities 24
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Medium 13% Low 88%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 24 secuirty vulnerabilities.


1) Information exposure (CVE-ID: CVE-2023-40645)

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to a possible missing permission check within the Messaging in Android. A local application can gain access to sensitive information.


2) Missing Authorization (CVE-ID: CVE-2023-40638)

The vulnerability allows a local application to crash the entire system.

The vulnerability exists due to a possible missing permission check within the Telecom service in Android. A local application can crash the entire system.


3) Improper Access Control (CVE-ID: CVE-2023-40654)

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to a possible missing permission check within the FW-PackageManager in Android. A remote attacker can trick the victim to open a specially crafted file and gain access to sensitive information.


4) Improper Access Control (CVE-ID: CVE-2023-40653)

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to a possible missing permission check within the FW-PackageManager in Android. A remote attacker can trick the victim to open a specially crafted file and gain access to sensitive information.


5) Out-of-bounds write (CVE-ID: CVE-2023-40652)

The vulnerability allows a local privileged application to damange or delete data.

The vulnerability exists due to a possible out of bounds write due to improper input validation within the jpg driver in Android. A local privileged application can damange or delete data.


6) Out-of-bounds write (CVE-ID: CVE-2023-40651)

The vulnerability allows a local privileged application to execute arbitrary code.

The vulnerability exists due to a possible out of bounds write due to a missing bounds check within the urild service in Android. A local privileged application can execute arbitrary code.


7) Information exposure (CVE-ID: CVE-2023-40650)

The vulnerability allows a remote attacker to read and manipulate data.

The vulnerability exists due to a possible missing permission check within the Telecom service in Android. A remote attacker can trick the victim to open a specially crafted file and read and manipulate data.


8) Information exposure (CVE-ID: CVE-2023-40649)

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to a possible missing permission check within the Messaging in Android. A local application can gain access to sensitive information.


9) Information exposure (CVE-ID: CVE-2023-40648)

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to a possible missing permission check within the Messaging in Android. A local application can gain access to sensitive information.


10) Information exposure (CVE-ID: CVE-2023-40647)

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to a possible missing permission check within the Messaging in Android. A local application can gain access to sensitive information.


11) Information exposure (CVE-ID: CVE-2023-40646)

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to a possible missing permission check within the Messaging in Android. A local application can gain access to sensitive information.


12) Information exposure (CVE-ID: CVE-2023-40644)

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to a possible missing permission check within the Messaging in Android. A local application can gain access to sensitive information.


13) Information exposure (CVE-ID: CVE-2023-40631)

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to a possible missing permission check within the Dialer in Android. A local application can gain access to sensitive information.


14) Information exposure (CVE-ID: CVE-2023-40643)

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to a possible missing permission check within the Messaging in Android. A local application can gain access to sensitive information.


15) Information exposure (CVE-ID: CVE-2023-40642)

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to a possible missing permission check within the Messaging in Android. A local application can gain access to sensitive information.


16) Information exposure (CVE-ID: CVE-2023-40641)

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to a possible missing permission check within the Messaging in Android. A local application can gain access to sensitive information.


17) Improper Access Control (CVE-ID: CVE-2023-40640)

The vulnerability allows a local application to read and manipulate data.

The vulnerability exists due to a possible missing permission check within the SoundRecorder service in Android. A local application can read and manipulate data.


18) Improper Access Control (CVE-ID: CVE-2023-40639)

The vulnerability allows a local application to read and manipulate data.

The vulnerability exists due to a possible missing permission check within the SoundRecorder service in Android. A local application can read and manipulate data.


19) Information exposure (CVE-ID: CVE-2023-40637)

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to a possible missing permission check within the telecom service in Android. A local application can gain access to sensitive information.


20) Comparison Logic is Vulnerable to Power Side-Channel Attacks (CVE-ID: CVE-2023-40636)

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to a possible way to write permission usage records of an app due to a missing permission check within the telecom service in Android. A local application can gain access to sensitive information.


21) Missing Authorization (CVE-ID: CVE-2023-40635)

The vulnerability allows a local application to perform service disruption.

The vulnerability exists due to a possible missing permission check within the linkturbo in Android. A local application can perform service disruption.


22) Information exposure (CVE-ID: CVE-2023-40634)

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to a possible missing permission check within the phasechecksercer in Android. A local application can gain access to sensitive information.


23) Information exposure (CVE-ID: CVE-2023-40633)

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to a possible missing permission check within the phasecheckserver in Android. A local application can gain access to sensitive information.


24) Use After Free (CVE-ID: CVE-2023-40632)

The vulnerability allows a local privileged application to execute arbitrary code.

The vulnerability exists due to a possible use after free due to a logic error within the jpg driver in Android. A local privileged application can execute arbitrary code.


Remediation

Install update from vendor's website.