465
VMScore

CVE-2015-7892

Published: 09/12/2019 Updated: 10/12/2019
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 465
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Stack-based buffer overflow in the m2m1shot_compat_ioctl32 function in the Samsung m2m1shot driver framework, as used in Samsung S6 Edge, allows local users to have unspecified impact via a large data.buf_out.num_planes value in an ioctl call.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

samsung m2m1shot driver -

Exploits

Source: codegooglecom/p/google-security-research/issues/detail?id=493 The Samsung m2m1shot driver framework is used to provide hardware acceleration for certain media functions, such as JPEG decoding and scaling images The driver endpoint (/dev/m2m1shot_jpeg) is accessible by the media server The Samsung S6 Edge is a 64-bit device, so ...