Vulnerability Name: | CVE-2013-4737 (CCN-91332) | ||||||||||||||||||||
Assigned: | 2013-09-05 | ||||||||||||||||||||
Published: | 2013-09-05 | ||||||||||||||||||||
Updated: | 2014-02-18 | ||||||||||||||||||||
Summary: | The CONFIG_STRICT_MEMORY_RWX implementation for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, does not properly consider certain memory sections, which makes it easier for attackers to bypass intended access restrictions by leveraging the presence of RWX memory at a fixed location. | ||||||||||||||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||||||||||||||
CVSS v2 Severity: | 9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C) 6.9 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
5.0 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||||||||||||||
Vulnerability Type: | CWE-264 | ||||||||||||||||||||
Vulnerability Consequences: | Bypass Security | ||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2013-4737 Source: CCN Type: BID-65630 Code Aurora Multiple Products 'CONFIG_STRICT_MEMORY_RWX' Security Bypass Vulnerability Source: XF Type: UNKNOWN configstrictmemoryrwx-cve20134737-bypass(91332) Source: CCN Type: QCIR-2013-00006-1 CONFIG_STRICT_MEMORY_RWX is not strictly enforced (CVE-2013-4737) Source: CONFIRM Type: Patch, Vendor Advisory https://www.codeaurora.org/projects/security-advisories/configstrictmemoryrwx-not-strictly-enforced-cve-2013-4737 | ||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||
| |||||||||||||||||||||
BACK |