Vulnerability Name: | CVE-2011-1350 (CCN-68265) | ||||||||||||||||
Assigned: | 2011-11-03 | ||||||||||||||||
Published: | 2011-11-03 | ||||||||||||||||
Updated: | 2013-02-07 | ||||||||||||||||
Summary: | The PowerVR SGX driver in Android before 2.3.6 allows attackers to obtain potentially sensitive information from kernel stack memory via an application that uses a crafted length parameter in a request to the pvrsrvkm device. | ||||||||||||||||
CVSS v3 Severity: | 6.2 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
| ||||||||||||||||
CVSS v2 Severity: | 7.1 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:N/A:N) 5.3 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:N/A:N/E:U/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||||||||||||
Vulnerability Type: | CWE-200 | ||||||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||||||
References: | Source: CCN Type: Google Support for Nexus Phones Web page Binaries for Nexus Phones Source: CCN Type: Android - Issue 21522 CVE-2011-1350: PowerVR SGX kernel memory leak Source: CONFIRM Type: Vendor Advisory http://code.google.com/p/android/issues/detail?id=21522 Source: MITRE Type: CNA CVE-2011-1350 Source: MISC Type: UNKNOWN http://jon.oberheide.org/files/levitator.c Source: CCN Type: Open Handset Alliance Web site Android Overview | Open Handset Alliance Source: XF Type: UNKNOWN powervr-sgx-kernel-memory-leak(68265) | ||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |