Vulnerability CVE-2013-6122


Published: 2013-11-12

Description:
goodix_tool.c in the Goodix gt915 touchscreen driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, does not properly synchronize updates to a global variable, which allows local users to bypass intended access restrictions or cause a denial of service (memory corruption) via crafted arguments to the procfs write handler.

See advisories in our WLB2 database:
Topic
Author
Date
Med.
Goodix GT915 Driver Memory Corruption / DoS / Privilege Escalation
Jonathan Salwan
08.11.2013

Type:

CWE-20

(Improper Input Validation)

CVSS2 => (AV:L/AC:M/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
6.9/10
10/10
3.4/10
Exploit range
Attack complexity
Authentication
Local
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete
Affected software
Qualcomm -> Quic mobile station modem kernel 

 References:
https://www.codeaurora.org/projects/security-advisories/multiple-memory-corruption-issues-and-race-condition-goodix-gt915-touchscreen-driver-procfs-handler
https://www.codeaurora.org/cgit/quic/la/kernel/msm-3.10/commit/?id=f53bcf29a6e7a66b3d935b8d562fa00829261f05
http://www.openwall.com/lists/oss-security/2013/11/08/1

Copyright 2024, cxsecurity.com

 

Back to Top