PT-2014-2863 · Linux · Linux Kernel

Jonathan Salwan

·

Publicado

2014-02-03

·

Atualizado

2014-02-07

·

CVE-2013-4739

CVSS v2.0

4.9

Média

VetorAV:L/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Linux kernel versions 3.x
Description The issue allows attackers to obtain sensitive information from kernel stack memory. This can be achieved through a crafted MSM MCR IOCTL EVT GET ioctl call related to drivers/media/platform/msm/camera v1/mercury/msm mercury sync.c, or a crafted MSM JPEG IOCTL EVT GET ioctl call related to drivers/media/platform/msm/camera v2/jpeg 10/msm jpeg sync.c.
Recommendations For Linux kernel version 3.x, consider restricting access to the MSM MCR IOCTL EVT GET and MSM JPEG IOCTL EVT GET ioctl calls until a patch is available. As a temporary workaround, disabling the msm mercury sync.c and msm jpeg sync.c functions may help minimize the risk of exploitation.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2013-4739

Produtos afetados

Linux Kernel