Out-of-bounds Write vulnerability while processing BC_TUI_CMD_SEND_RESOURCE_DATA_ARRAY command in bc_tui trustlet from Samsung Blockchain Keystore prior to version 1.3.12.1 allows local attacker to execute arbitrary code.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://security.samsungmobile.com/serviceWeb.smsb?year=2023&month=05 | vendor advisory |