6.8
CVSSv2

CVE-2012-4220

Published: 30/11/2012 Updated: 10/10/2013
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 606
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

diagchar_core.c in the Qualcomm Innovation Center (QuIC) Diagnostics (aka DIAG) kernel-mode driver for Android 2.3 up to and including 4.2 allows malicious users to execute arbitrary code or cause a denial of service (incorrect pointer dereference) via an application that uses crafted arguments in a local diagchar_ioctl call.

Vulnerable Product Search on Vulmon Subscribe to Product

google android 2.3.3

google android 2.3.5

google android 2.3.7

google android 3.2.2

google android 3.2.6

google android 4.0.1

google android 2.3

google android 3.1

google android 3.2

google android 3.0

google android 2.3.1

google android 2.3.2

google android 4.0

google android 4.1

google android 4.0.4

google android 4.0.3

google android 2.3.4

google android 2.3.6

google android 3.2.1

google android 3.2.4

google android 4.0.2

google android 4.2

Github Repositories

exploit for CVE-2012-4220 working on zte-open

root-zte-open exploit for CVE-2012-4220 working on zte-open Original Advisory: wwwcodeauroraorg/projects/security-advisories/multiple-issues-diagkgsl-system-call-handling-cve-2012-4220-cve-2012 Original Exploit: githubcom/hiikezoe/break_setresuid Build $ ndk-build NDK_PROJECT_PATH= APP_BUILD_SCRIPT=/Androidmk

root-zte-open exploit for CVE-2012-4220 working on zte-open Original Advisory: wwwcodeauroraorg/projects/security-advisories/multiple-issues-diagkgsl-system-call-handling-cve-2012-4220-cve-2012 Original Exploit: githubcom/hiikezoe/break_setresuid Build $ ndk-build NDK_PROJECT_PATH= APP_BUILD_SCRIPT=/Androidmk

Awesome Stars A curated list of my GitHub stars! Generated by starred Contents ANTLR API Blueprint AppleScript Assembly Awk C C# C++ COBOL CSS Clojure CoffeeScript Common Lisp D Dockerfile Eagle Elixir Elm Emacs Lisp Erlang F# Go Groff Groovy HTML Haskell Java JavaScript Jupyter Notebook Kotlin Lua Makefile Matlab OCaml Objective-C Objective-C++ Others Oz PHP PLpgSQL Perl