PT-2013-4124 · Google+1 · Android+1

Dan Rosenberg

+1

·

Publicado

2013-04-13

·

Atualizado

2013-04-15

·

CVE-2013-3051

CVSS v2.0

6.2

Média

VetorAV:L/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions TrustZone kernel on Motorola devices with Android 4.1.2
Description The issue allows local users to unlock the bootloader by using kernel mode to perform crafted 0x9 and 0x2 SMC operations, due to the lack of verification of the association between a certain physical-address argument and a memory region.
Recommendations For the affected Motorola devices with Android 4.1.2, consider restricting access to kernel mode operations until a patch is available. As a temporary workaround, avoid using the crafted SMC operations 0x9 and 0x2 to prevent potential exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2013-3051

Produtos afetados

Android
Trustzone