PT-2012-1214 · Samsung+2 · Samsung Galaxy S2+5
Alephzain
·
Published
2012-12-17
·
Updated
2012-12-21
·
CVE-2012-6422
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Samsung Galaxy S2 (affected versions not specified)
Samsung Galaxy Note 2 (affected versions not specified)
MEIZU MX (affected versions not specified)
Description
The issue is related to weak permissions in the kernel of certain Android devices, specifically those running Exynos 4210 or 4412 processors. This weakness allows attackers to read or write arbitrary physical memory, potentially gaining privileges through a crafted application. The vulnerability is associated with inadequate access control in the device's software.
Recommendations
For Samsung Galaxy S2, consider restricting access to the /dev/exynos-mem file as a temporary workaround until a patch is available.
For Samsung Galaxy Note 2, avoid using applications that may exploit the weak permissions in the kernel until the issue is resolved.
For MEIZU MX, as a temporary mitigation measure, consider disabling any functionality that relies on the Exynos processor's memory access until a fix is provided.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Android
Exynos 4210
Exynos 4412
Meizu Mx
Samsung Galaxy Note 2
Samsung Galaxy S2