CVE-2022-23747

In Sony Xperia series 1, 5, and Pro, an out of bound memory access can occur due to lack of validation of the number of frames being passed during music playback.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:sony:xperia_1_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:sony:xperia_1:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:sony:xperia_5_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:sony:xperia_5:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:sony:xperia_pro_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:sony:xperia_pro:-:*:*:*:*:*:*:*

History

21 Nov 2024, 06:49

Type Values Removed Values Added
References () https://cpr-zero.checkpoint.com/vulns/cprid-2191/ - Exploit, Third Party Advisory () https://cpr-zero.checkpoint.com/vulns/cprid-2191/ - Exploit, Third Party Advisory
References () https://research.checkpoint.com/2022/bad-alac-one-codec-to-hack-the-whole-world/ - Exploit, Third Party Advisory () https://research.checkpoint.com/2022/bad-alac-one-codec-to-hack-the-whole-world/ - Exploit, Third Party Advisory

Information

Published : 2022-08-17 21:15

Updated : 2024-11-21 06:49


NVD link : CVE-2022-23747

Mitre link : CVE-2022-23747

CVE.ORG link : CVE-2022-23747


JSON object : View

Products Affected

sony

  • xperia_1
  • xperia_pro
  • xperia_1_firmware
  • xperia_5_firmware
  • xperia_pro_firmware
  • xperia_5
CWE
CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')