Lucene search

K
nvd[email protected]NVD:CVE-2013-4736
HistoryFeb 10, 2014 - 6:15 p.m.

CVE-2013-4736

2014-02-1018:15:10
CWE-189
web.nvd.nist.gov

7.8 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

6.6 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

50.4%

Multiple integer overflows in the JPEG engine drivers in the MSM camera driver for the Linux kernel 2.6.x and 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allow attackers to cause a denial of service (system crash) via a large number of commands in an ioctl call, related to (1) camera_v1/gemini/msm_gemini_sync.c, (2) camera_v2/gemini/msm_gemini_sync.c, (3) camera_v2/jpeg_10/msm_jpeg_sync.c, (4) gemini/msm_gemini_sync.c, (5) jpeg_10/msm_jpeg_sync.c, and (6) mercury/msm_mercury_sync.c.

Affected configurations

NVD
Node
codeauroraandroid-msmMatch3.2.54
OR
codeauroraandroid-msmMatch3.4.72
OR
codeauroraandroid-msmMatch3.4.73
OR
codeauroraandroid-msmMatch3.4.74
OR
codeauroraandroid-msmMatch3.4.75
OR
codeauroraandroid-msmMatch3.4.76
OR
codeauroraandroid-msmMatch3.4.77
OR
codeauroraandroid-msmMatch3.4.78
OR
codeauroraandroid-msmMatch3.4.79
OR
codeauroraandroid-msmMatch3.10.22
OR
codeauroraandroid-msmMatch3.10.23
OR
codeauroraandroid-msmMatch3.10.24
OR
codeauroraandroid-msmMatch3.10.25
OR
codeauroraandroid-msmMatch3.10.26
OR
codeauroraandroid-msmMatch3.10.27
OR
codeauroraandroid-msmMatch3.10.28
OR
codeauroraandroid-msmMatch3.10.29
OR
codeauroraandroid-msmMatch3.12.3
OR
codeauroraandroid-msmMatch3.12.4
OR
codeauroraandroid-msmMatch3.12.5
OR
codeauroraandroid-msmMatch3.12.6
OR
codeauroraandroid-msmMatch3.12.7
OR
codeauroraandroid-msmMatch3.12.8
OR
codeauroraandroid-msmMatch3.12.9
OR
codeauroraandroid-msmMatch3.12.10
OR
codeauroraandroid-msmMatch3.13
OR
codeauroraandroid-msmMatch3.13rc1
OR
codeauroraandroid-msmMatch3.13rc2
OR
codeauroraandroid-msmMatch3.13rc3
OR
codeauroraandroid-msmMatch3.13rc4
OR
codeauroraandroid-msmMatch3.13rc5
OR
codeauroraandroid-msmMatch3.13rc6
OR
codeauroraandroid-msmMatch3.13rc7
OR
codeauroraandroid-msmMatch3.13rc8
OR
codeauroraandroid-msmMatch3.13.1
OR
codeauroraandroid-msmMatch3.13.2
OR
codeauroraandroid-msmMatch3.14rc1
OR
codeauroraandroid-msmMatch3.14rc2

7.8 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

6.6 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

50.4%