Lucene search

K
cve[email protected]CVE-2013-6392
HistoryNov 30, 2013 - 2:55 a.m.

CVE-2013-6392

2013-11-3002:55:04
CWE-399
web.nvd.nist.gov
21
cve-2013-6392
genlock driver
linux kernel
qualcomm innovation center
android
msm devices
security vulnerability

4.9 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:C/I:N/A:N

5.7 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

5.1%

The genlock_dev_ioctl function in genlock.c in the Genlock driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, does not properly initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory via a crafted GENLOCK_IOC_EXPORT ioctl call.

Affected configurations

NVD
Node
codeauroraandroid-msmMatch3.2.54
OR
codeauroraandroid-msmMatch3.4.72
OR
codeauroraandroid-msmMatch3.4.73
OR
codeauroraandroid-msmMatch3.4.74
OR
codeauroraandroid-msmMatch3.4.75
OR
codeauroraandroid-msmMatch3.4.76
OR
codeauroraandroid-msmMatch3.4.77
OR
codeauroraandroid-msmMatch3.4.78
OR
codeauroraandroid-msmMatch3.4.79
OR
codeauroraandroid-msmMatch3.10.22
OR
codeauroraandroid-msmMatch3.10.23
OR
codeauroraandroid-msmMatch3.10.24
OR
codeauroraandroid-msmMatch3.10.25
OR
codeauroraandroid-msmMatch3.10.26
OR
codeauroraandroid-msmMatch3.10.27
OR
codeauroraandroid-msmMatch3.10.28
OR
codeauroraandroid-msmMatch3.10.29
OR
codeauroraandroid-msmMatch3.12.3
OR
codeauroraandroid-msmMatch3.12.4
OR
codeauroraandroid-msmMatch3.12.5
OR
codeauroraandroid-msmMatch3.12.6
OR
codeauroraandroid-msmMatch3.12.7
OR
codeauroraandroid-msmMatch3.12.8
OR
codeauroraandroid-msmMatch3.12.9
OR
codeauroraandroid-msmMatch3.12.10
OR
codeauroraandroid-msmMatch3.13
OR
codeauroraandroid-msmMatch3.13rc1
OR
codeauroraandroid-msmMatch3.13rc2
OR
codeauroraandroid-msmMatch3.13rc3
OR
codeauroraandroid-msmMatch3.13rc4
OR
codeauroraandroid-msmMatch3.13rc5
OR
codeauroraandroid-msmMatch3.13rc6
OR
codeauroraandroid-msmMatch3.13rc7
OR
codeauroraandroid-msmMatch3.13rc8
OR
codeauroraandroid-msmMatch3.13.1
OR
codeauroraandroid-msmMatch3.13.2
OR
codeauroraandroid-msmMatch3.14rc1
OR
codeauroraandroid-msmMatch3.14rc2

4.9 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:C/I:N/A:N

5.7 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

5.1%