Vulnerability Name: | CVE-2013-4739 (CCN-88034) | ||||||||||||||||||||||||||||||||||||
Assigned: | 2013-10-15 | ||||||||||||||||||||||||||||||||||||
Published: | 2013-10-15 | ||||||||||||||||||||||||||||||||||||
Updated: | 2014-02-07 | ||||||||||||||||||||||||||||||||||||
Summary: | The MSM camera driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to obtain sensitive information from kernel stack memory via (1) a crafted MSM_MCR_IOCTL_EVT_GET ioctl call, related to drivers/media/platform/msm/camera_v1/mercury/msm_mercury_sync.c, or (2) a crafted MSM_JPEG_IOCTL_EVT_GET ioctl call, related to drivers/media/platform/msm/camera_v2/jpeg_10/msm_jpeg_sync.c. | ||||||||||||||||||||||||||||||||||||
CVSS v3 Severity: | 4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||||||||||||||||||||||||||||||
CVSS v2 Severity: | 4.9 Medium (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:N/A:N) 3.7 Low (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:N/A:N/E:U/RL:OF/RC:C)
1.6 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||||||||||||||||||||||||||||||||
Vulnerability Type: | CWE-200 | ||||||||||||||||||||||||||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2013-4739 Source: CCN Type: oss-sec Mailing List, Tue, 15 Oct 2013 18:44:58 +0100 Report - Stack-based buffer overflow and memory disclosure in camera driver (CVE-2013-4748 CVE-2013-4739) Source: MLIST Type: UNKNOWN [oss-security] 20131015 Report - Stack-based buffer overflow and memory disclosure in camera driver (CVE-2013-4748 CVE-2013-4739) Source: CCN Type: Qualcomm Web site Wireless Technology & Innovation | Mobile Technology | Qualcomm Source: XF Type: UNKNOWN android-jpeg-cve20134739-info-disclosure(88034) Source: CCN Type: QCIR-2013-00008-1 Stack-based buffer overflow and memory disclosure in camera driver (CVE-2013-4738 CVE-2013-4739) Source: CONFIRM Type: Vendor Advisory https://www.codeaurora.org/projects/security-advisories/stack-based-buffer-overflow-and-memory-disclosure-camera-driver-cve-2013-4748-cve-2013-4739 Source: CCN Type: WhiteSource Vulnerability Database CVE-2013-4739 | ||||||||||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||
BACK |