PT-2017-8447 · Qualcomm+1 · Msm8974Pro+3

Berry Cheng

·

Publicado

2017-02-01

·

Atualizado

2017-03-04

·

CVE-2016-4038

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Samsung devices with Android KK(4.4) or L and an APQ8084, MSM8974, or MSM8974pro chipset
Description The issue is related to an array index error in the msm sensor config function. This error can be triggered by local users via the gpio config.gpio name value, potentially leading to unspecified impact.
Recommendations For Samsung devices with Android KK(4.4) or L and an APQ8084, MSM8974, or MSM8974pro chipset, consider restricting access to the msm sensor config function until a patch is available. As a temporary workaround, avoid using the gpio config.gpio name value in sensitive operations to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-4038

Produtos afetados

Apq8084
Android
Msm8974
Msm8974Pro