Vulnerability Note VU#702452
Qualcomm Android OS kernel privilege escalation and denial of service vulnerabilites
Overview
Android OS kernels running on certain Qualcomm devices contain multiple vulnerabilities which could allow an attacker to cause privilege escalation or Denial of Service (DoS).
Description
The Qualcomm Innovation Center, Inc. advisory states: Summary: |
Impact
By convincing a user to install a specially crafted android application, a remote attacker may be able to cause a privilege escalation or Denial of Service (DoS) allowing them to gain control of the affected device. |
Solution
Update |
Vendor Information (Learn More)
| Vendor | Status | Date Notified | Date Updated |
|---|---|---|---|
| QUALCOMM Incorporated | Affected | 01 Nov 2012 | 30 Nov 2012 |
CVSS Metrics (Learn More)
| Group | Score | Vector |
|---|---|---|
| Base | 6.0 | AV:L/AC:H/Au:S/C:C/I:C/A:C |
| Temporal | 4.7 | E:POC/RL:OF/RC:C |
| Environmental | 5.2 | CDP:L/TD:H/CR:ND/IR:ND/AR:ND |
References
- https://www.codeaurora.org/participate/security-advisories/cve-2012-4220-cve-2012-4221-cve-2012-4222/
- https://www.codeaurora.org/patches/quic/la/.PATCH_17010_jweEF843feG.tar.gz
Credit
Thanks to giantpune@gmail.com for reporting this vulnerability.
This document was written by Michael Orlando.
Other Information
- CVE IDs: CVE-2012-4220 CVE-2012-4221 CVE-2012-4222
- Date Public: 15 Nov 2012
- Date First Published: 07 Dec 2012
- Date Last Updated: 07 Dec 2012
- Document Revision: 14
Feedback
If you have feedback, comments, or additional information about this vulnerability, please send us email.