Lucene search

K
androidAlephzain <[email protected]>ANDROID:QUALCOMM_INTEGER_OVERFLOW_CAMERA
HistoryAug 29, 2013 - 12:00 a.m.

Qualcomm Integer overflow camera

2013-08-2900:00:00
alephzain <[email protected]>
www.androidvulnerabilities.org
12

0.001 Low

EPSS

Percentile

50.4%

Integer overflow and signedness issue in camera JPEG engines (CVE-2013-4736) QCIR-2013-00005-1: The JPEG engines that are part of the camera driver provide an ioctl system call interface to user space clients for communication. When processing hardware commands ioctl calls, the drivers are incorrectly handling the number of commands included in the user space payload. This can lead to an integer overflow which subsequently results in the driver attempting to process hardware commands from out-of-bounds memory which can cause the kernel to crash. The same code also suffered from incorrectly treating the number of hardware commands as signed.
Gemini JPEG encoder, Mercury JPEG decoder, and Jpeg1.0 common encoder/decoder contain an unspecified integer overflow condition during the handling of hardware command IOCTL calls that may allow a local attacker to cause a denial of service or potentially execute of arbitrary code.

0.001 Low

EPSS

Percentile

50.4%

Related for ANDROID:QUALCOMM_INTEGER_OVERFLOW_CAMERA