Overview
Android OS kernels running on certain Qualcomm devices contain multiple vulnerabilities which could allow an attacker to cause privilege escalation or Denial of Service (DoS).
Description
The Qualcomm Innovation Center, Inc. advisory states: Summary: |
Impact
By convincing a user to install a specially crafted android application, a remote attacker may be able to cause a privilege escalation or Denial of Service (DoS) allowing them to gain control of the affected device. |
Solution
Update |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | 6.6 | AV:L/AC:M/Au:S/C:C/I:C/A:C |
Temporal | 5.2 | E:POC/RL:OF/RC:C |
Environmental | 3.9 | CDP:ND/TD:M/CR:ND/IR:ND/AR:ND |
References
Acknowledgements
Thanks to giantpune@gmail.com for reporting this vulnerability.
This document was written by Michael Orlando.
Other Information
CVE IDs: | CVE-2012-4220, CVE-2012-4221, CVE-2012-4222 |
Date Public: | 2012-11-15 |
Date First Published: | 2012-12-07 |
Date Last Updated: | 2014-08-15 02:30 UTC |
Document Revision: | 16 |