PT-2012-1214 · Samsung+2 · Samsung Galaxy S2+5
Alephzain
·
Publicado
2012-12-17
·
Atualizado
2012-12-21
·
CVE-2012-6422
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Samsung Galaxy S2 (affected versions not specified)
Samsung Galaxy Note 2 (affected versions not specified)
MEIZU MX (affected versions not specified)
Description
The issue is related to weak permissions in the kernel of certain Android devices, specifically those running Exynos 4210 or 4412 processors. This weakness allows attackers to read or write arbitrary physical memory, potentially gaining privileges through a crafted application. The vulnerability is associated with inadequate access control in the device's software.
Recommendations
For Samsung Galaxy S2, consider restricting access to the /dev/exynos-mem file as a temporary workaround until a patch is available.
For Samsung Galaxy Note 2, avoid using applications that may exploit the weak permissions in the kernel until the issue is resolved.
For MEIZU MX, as a temporary mitigation measure, consider disabling any functionality that relies on the Exynos processor's memory access until a fix is provided.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Android
Exynos 4210
Exynos 4412
Meizu Mx
Samsung Galaxy Note 2
Samsung Galaxy S2