CVE-2013-2597

Published Aug 31, 2014

Last updated 10 years ago

Overview

Description
Stack-based buffer overflow in the acdb_ioctl function in audio_acdb.c in the acdb audio driver for the Linux kernel 2.6.x and 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to gain privileges via an application that leverages /dev/msm_acdb access and provides a large size value in an ioctl argument.
Source
cve@mitre.org
NVD status
Analyzed

Risk scores

CVSS 2.0

Type
Primary
Base score
7.2
Impact score
10
Exploitability score
3.9
Vector string
AV:L/AC:L/Au:N/C:C/I:C/A:C

Known exploits

Data from CISA

Vulnerability name
Code Aurora ACDB Audio Driver Stack-based Buffer Overflow Vulnerability
Exploit added on
Sep 15, 2022
Exploit action due
Oct 6, 2022
Required action
Apply updates per vendor instructions.

Weaknesses

nvd@nist.gov
CWE-119

Social media

Hype score
Not currently trending

Configurations