PT-2012-1214 · Samsung+2 · Samsung Galaxy S2+5

Alephzain

·

Published

2012-12-17

·

Updated

2012-12-21

·

CVE-2012-6422

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Samsung Galaxy S2 (affected versions not specified) Samsung Galaxy Note 2 (affected versions not specified) MEIZU MX (affected versions not specified)
Description The issue is related to weak permissions in the kernel of certain Android devices, specifically those running Exynos 4210 or 4412 processors. This weakness allows attackers to read or write arbitrary physical memory, potentially gaining privileges through a crafted application. The vulnerability is associated with inadequate access control in the device's software.
Recommendations For Samsung Galaxy S2, consider restricting access to the /dev/exynos-mem file as a temporary workaround until a patch is available. For Samsung Galaxy Note 2, avoid using applications that may exploit the weak permissions in the kernel until the issue is resolved. For MEIZU MX, as a temporary mitigation measure, consider disabling any functionality that relies on the Exynos processor's memory access until a fix is provided. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-04418
CVE-2012-6422

Affected Products

Android
Exynos 4210
Exynos 4412
Meizu Mx
Samsung Galaxy Note 2
Samsung Galaxy S2