PT-2019-7213 · Samsung · Samsung M2M1Shot Driver Framework

Published

2019-12-09

·

Updated

2019-12-10

·

CVE-2015-7892

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Samsung m2m1shot driver framework version (affected versions not specified)
Description The issue is related to a stack-based buffer overflow in the m2m1shot compat ioctl32 function. This function is part of the Samsung m2m1shot driver framework used in devices such as the Samsung S6 Edge. The overflow can be triggered by a local user via a large data.buf out.num planes value in an ioctl call.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-7892

Affected Products

Samsung M2M1Shot Driver Framework