2014-08-31 12:55:03 2014-09-02 20:44:44

app/aboot/aboot.c in the Little Kernel (LK) bootloader, as distributed with Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to overwrite signature-verification code via crafted boot-image load-destination header values that specify memory locations within bootloader memory.

Vector

LOCAL

Complexity

LOW

Authentication

NONE

Confidentiality

NONE

Integrity

COMPLETE

Availability

COMPLETE
Codeaurora Android-msm 3.12.23 (not an official CPE) Codeaurora Android-msm 3.2.59 (not an official CPE) Codeaurora Android-msm 3.12.24 (not an official CPE) Codeaurora Android-msm 3.12.25 (not an official CPE) Codeaurora Android-msm 3.12.26 (not an official CPE) Codeaurora Android-msm 3.12.20 (not an official CPE) Codeaurora Android-msm 3.12.21 (not an official CPE) Codeaurora Android-msm 3.12.22 (not an official CPE) Codeaurora Android-msm 3.2.55 (not an official CPE) Codeaurora Android-msm 3.2.54 (not an official CPE) Codeaurora Android-msm 3.2.56 (not an official CPE) Codeaurora Android-msm 3.13 Rc3 (not an official CPE) Codeaurora Android-msm 3.2.58 (not an official CPE) Codeaurora Android-msm 3.13 Rc4 (not an official CPE) Codeaurora Android-msm 3.14 Rc3 (not an official CPE) Codeaurora Android-msm 3.2.57 (not an official CPE) Codeaurora Android-msm 3.15 Rc3 (not an official CPE) Codeaurora Android-msm 3.13 Rc1 (not an official CPE) Codeaurora Android-msm 3.14 Rc4 (not an official CPE) Codeaurora Android-msm 3.15.10 (not an official CPE) Codeaurora Android-msm 3.2.61 (not an official CPE) Codeaurora Android-msm 3.2.60 (not an official CPE) Codeaurora Android-msm 3.2.62 (not an official CPE) Codeaurora Android-msm 3.14.14 (not an official CPE) Codeaurora Android-msm 3.14.16 (not an official CPE) Codeaurora Android-msm 3.14.15 (not an official CPE) Codeaurora Android-msm 3.14.13 (not an official CPE) Codeaurora Android-msm 3.14.12 (not an official CPE) Codeaurora Android-msm 3.14.11 (not an official CPE) Codeaurora Android-msm 3.10.29 (not an official CPE) Codeaurora Android-msm 3.10.27 (not an official CPE) Codeaurora Android-msm 2.6.29 (not an official CPE) Codeaurora Android-msm 3.10.28 (not an official CPE) Codeaurora Android-msm 3.10.26 (not an official CPE) Codeaurora Android-msm 3.13.11 (not an official CPE) Codeaurora Android-msm 3.10.25 (not an official CPE) Codeaurora Android-msm 3.13.10 (not an official CPE) Codeaurora Android-msm 3.10.23 (not an official CPE) Codeaurora Android-msm 3.10.24 (not an official CPE) Codeaurora Android-msm 3.10.22 (not an official CPE) Codeaurora Android-msm 3.15 Rc7 (not an official CPE) Codeaurora Android-msm 3.12.5 (not an official CPE) Codeaurora Android-msm 3.13 Rc5 (not an official CPE) Codeaurora Android-msm 3.14 Rc8 (not an official CPE) Codeaurora Android-msm 3.15 Rc2 (not an official CPE) Codeaurora Android-msm 3.13 Rc8 (not an official CPE) Codeaurora Android-msm 3.14 Rc7 (not an official CPE) Codeaurora Android-msm 3.15 Rc1 (not an official CPE) Codeaurora Android-msm 3.13 Rc7 (not an official CPE) Codeaurora Android-msm 3.14 Rc2 (not an official CPE) Codeaurora Android-msm 3.15 Rc4 (not an official CPE) Codeaurora Android-msm 3.13 Rc2 (not an official CPE) Codeaurora Android-msm 3.14 Rc1 (not an official CPE) Codeaurora Android-msm 3.16 (not an official CPE) Codeaurora Android-msm 3.15 Rc6 (not an official CPE) Codeaurora Android-msm 3.15 Rc5 (not an official CPE) Codeaurora Android-msm 3.14 Rc6 (not an official CPE) Codeaurora Android-msm 3.15 Rc8 (not an official CPE) Codeaurora Android-msm 3.13 Rc6 (not an official CPE) Codeaurora Android-msm 3.14 Rc5 (not an official CPE) Codeaurora Android-msm 3.17 Rc1 (not an official CPE) Codeaurora Android-msm 3.16 Rc2 (not an official CPE) Codeaurora Android-msm 3.16 Rc1 (not an official CPE) Codeaurora Android-msm 3.12.6 (not an official CPE) Codeaurora Android-msm 3.16 Rc4 (not an official CPE) Codeaurora Android-msm 3.12.7 (not an official CPE) Codeaurora Android-msm 3.16 Rc3 (not an official CPE) Codeaurora Android-msm 3.12.8 (not an official CPE) Codeaurora Android-msm 3.16 Rc6 (not an official CPE) Codeaurora Android-msm 3.12.9 (not an official CPE) Codeaurora Android-msm 3.16 Rc5 (not an official CPE) Codeaurora Android-msm 3.12.3 (not an official CPE) Codeaurora Android-msm 3.16 Rc7 (not an official CPE) Codeaurora Android-msm 3.12.4 (not an official CPE) Codeaurora Android-msm 3.10.37 (not an official CPE) Codeaurora Android-msm 3.10.38 (not an official CPE) Codeaurora Android-msm 3.10.39 (not an official CPE) Codeaurora Android-msm 3.10.32 (not an official CPE) Codeaurora Android-msm 3.14.10 (not an official CPE) Codeaurora Android-msm 3.10.36 (not an official CPE) Codeaurora Android-msm 3.10.30 (not an official CPE) Codeaurora Android-msm 3.14 (not an official CPE) Codeaurora Android-msm 3.10.31 (not an official CPE) Codeaurora Android-msm 3.13 (not an official CPE) Codeaurora Android-msm 3.15 (not an official CPE) Codeaurora Android-msm 3.10.33 (not an official CPE) Codeaurora Android-msm 3.10 (not an official CPE) Codeaurora Android-msm 3.10.35 (not an official CPE) Codeaurora Android-msm 3.4.83 (not an official CPE) Codeaurora Android-msm 3.4.102 (not an official CPE) Codeaurora Android-msm 3.4.101 (not an official CPE) Codeaurora Android-msm 3.4.85 (not an official CPE) Codeaurora Android-msm 3.4.100 (not an official CPE) Codeaurora Android-msm 3.4.84 (not an official CPE) Codeaurora Android-msm 3.4.87 (not an official CPE) Codeaurora Android-msm 3.4.89 (not an official CPE) Codeaurora Android-msm 3.4.88 (not an official CPE) Codeaurora Android-msm 3.4.103 (not an official CPE) Codeaurora Android-msm 3.4.86 (not an official CPE) Codeaurora Android-msm 3.10.50 (not an official CPE) Codeaurora Android-msm 3.10.46 (not an official CPE) Codeaurora Android-msm 3.10.45 (not an official CPE) Codeaurora Android-msm 3.10.44 (not an official CPE) Codeaurora Android-msm 3.10.42 (not an official CPE) Codeaurora Android-msm 3.10.41 (not an official CPE) Codeaurora Android-msm 3.10.40 (not an official CPE) Codeaurora Android-msm 3.10.47 (not an official CPE) Codeaurora Android-msm 3.4.93 (not an official CPE) Codeaurora Android-msm 3.10.43 (not an official CPE) Codeaurora Android-msm 3.4.90 (not an official CPE) Codeaurora Android-msm 3.10.49 (not an official CPE) Codeaurora Android-msm 3.4.91 (not an official CPE) Codeaurora Android-msm 3.10.48 (not an official CPE) Codeaurora Android-msm 3.4.92 (not an official CPE) Codeaurora Android-msm 3.4.74 (not an official CPE) Codeaurora Android-msm 3.4.73 (not an official CPE) Codeaurora Android-msm 3.4.72 (not an official CPE) Codeaurora Android-msm 3.4.79 (not an official CPE) Codeaurora Android-msm 3.4.78 (not an official CPE) Codeaurora Android-msm 3.4.77 (not an official CPE) Codeaurora Android-msm 3.4.76 (not an official CPE) Codeaurora Android-msm 3.4.75 (not an official CPE) Codeaurora Android-msm 3.14.9 (not an official CPE) Codeaurora Android-msm 3.14.8 (not an official CPE) Codeaurora Android-msm 3.10.51 (not an official CPE) Codeaurora Android-msm 3.10.53 (not an official CPE) Codeaurora Android-msm 3.10.52 (not an official CPE) Codeaurora Android-msm 3.14.3 (not an official CPE) Codeaurora Android-msm 3.14.2 (not an official CPE) Codeaurora Android-msm 3.14.1 (not an official CPE) Codeaurora Android-msm 3.4.82 (not an official CPE) Codeaurora Android-msm 3.14.7 (not an official CPE) Codeaurora Android-msm 3.4.80 (not an official CPE) Codeaurora Android-msm 3.14.6 (not an official CPE) Codeaurora Android-msm 3.4.81 (not an official CPE) Codeaurora Android-msm 3.14.5 (not an official CPE) Codeaurora Android-msm 3.14.4 (not an official CPE) Codeaurora Android-msm 3.13.1 (not an official CPE) Codeaurora Android-msm 3.13.8 (not an official CPE) Codeaurora Android-msm 3.13.3 (not an official CPE) Codeaurora Android-msm 3.13.2 (not an official CPE) Codeaurora Android-msm 3.13.5 (not an official CPE) Codeaurora Android-msm 3.13.7 (not an official CPE) Codeaurora Android-msm 3.13.6 (not an official CPE) Codeaurora Android-msm 3.13.9 (not an official CPE) Codeaurora Android-msm 3.13.4 (not an official CPE) Codeaurora Android-msm 3.4.99 (not an official CPE) Codeaurora Android-msm 3.4.98 (not an official CPE) Codeaurora Android-msm 3.4.96 (not an official CPE) Codeaurora Android-msm 3.4.95 (not an official CPE) Codeaurora Android-msm 3.4.94 (not an official CPE) Codeaurora Android-msm 3.4.97 (not an official CPE) Codeaurora Android-msm 3.12.16 (not an official CPE) Codeaurora Android-msm 3.12.11 (not an official CPE) Codeaurora Android-msm 3.15.2 (not an official CPE) Codeaurora Android-msm 3.12.10 (not an official CPE) Codeaurora Android-msm 3.16.1 (not an official CPE) Codeaurora Android-msm 3.15.9 (not an official CPE) Codeaurora Android-msm 3.12.13 (not an official CPE) Codeaurora Android-msm 3.15.8 (not an official CPE) Codeaurora Android-msm 3.15.7 (not an official CPE) Codeaurora Android-msm 3.12.15 (not an official CPE) Codeaurora Android-msm 3.12.14 (not an official CPE) Codeaurora Android-msm 3.15.5 (not an official CPE) Codeaurora Android-msm 3.12.17 (not an official CPE) Codeaurora Android-msm 3.15.4 (not an official CPE) Codeaurora Android-msm 3.15.3 (not an official CPE) Codeaurora Android-msm 3.12.19 (not an official CPE) Codeaurora Android-msm 3.12.18 (not an official CPE) Codeaurora Android-msm 3.15.1 (not an official CPE) Codeaurora Android-msm 3.12.12 (not an official CPE) Codeaurora Android-msm 3.15.6 (not an official CPE)

Improper Input Validation (ID 20)

Related CAPEC 58 Buffer Overflow via Environment Variables (CAPEC-ID 10) Server Side Include (SSI) Injection (CAPEC-ID 101) Cross Zone Scripting (CAPEC-ID 104) Cross Site Scripting through Log Files (CAPEC-ID 106) Command Line Execution through SQL Injection (CAPEC-ID 108) Object Relational Mapping Injection (CAPEC-ID 109) SQL Injection through SOAP Parameter Tampering (CAPEC-ID 110) Subverting Environment Variable Values (CAPEC-ID 13) Format String Injection (CAPEC-ID 135) LDAP Injection (CAPEC-ID 136) Relative Path Traversal (CAPEC-ID 139) Client-side Injection-induced Buffer Overflow (CAPEC-ID 14) Variable Manipulation (CAPEC-ID 171) Embedding Scripts in Non-Script Elements (CAPEC-ID 18) Flash Injection (CAPEC-ID 182) Cross-Site Scripting Using Alternate Syntax (CAPEC-ID 199) Exploiting Trust in Client (aka Make the Client Invisible) (CAPEC-ID 22) XML Nested Payloads (CAPEC-ID 230) XML Oversized Payloads (CAPEC-ID 231) Filter Failure through Buffer Overflow (CAPEC-ID 24) Cross-Site Scripting via Encoded URI Schemes (CAPEC-ID 244) XML Injection (CAPEC-ID 250) Environment Variable Manipulation (CAPEC-ID 264) Global variable manipulation (CAPEC-ID 265) Leverage Alternate Encoding (CAPEC-ID 267) Fuzzing (CAPEC-ID 28) Using Leading 'Ghost' Character Sequences to Bypass Input Filters (CAPEC-ID 3) Accessing/Intercepting/Modifying HTTP Cookies (CAPEC-ID 31) Embedding Scripts in HTTP Query Strings (CAPEC-ID 32) MIME Conversion (CAPEC-ID 42) Exploiting Multiple Input Interpretation Layers (CAPEC-ID 43) Buffer Overflow via Symbolic Links (CAPEC-ID 45) Overflow Variables and Tags (CAPEC-ID 46) Buffer Overflow via Parameter Expansion (CAPEC-ID 47) Signature Spoof (CAPEC-ID 473) XML Client-Side Attack (CAPEC-ID 484) Embedding NULL Bytes (CAPEC-ID 52) Postfix, Null Terminate, and Backslash (CAPEC-ID 53) Simple Script Injection (CAPEC-ID 63) Using Slashes and URL Encoding Combined to Bypass Validation Logic (CAPEC-ID 64) SQL Injection (CAPEC-ID 66) String Format Overflow in syslog() (CAPEC-ID 67) Blind SQL Injection (CAPEC-ID 7) Using Unicode Encoding to Bypass Validation Logic (CAPEC-ID 71) URL Encoding (CAPEC-ID 72) User-Controlled Filename (CAPEC-ID 73) Using Escaped Slashes in Alternate Encoding (CAPEC-ID 78) Using Slashes in Alternate Encoding (CAPEC-ID 79) Buffer Overflow in an API Call (CAPEC-ID 8) Using UTF-8 Encoding to Bypass Validation Logic (CAPEC-ID 80) Web Logs Tampering (CAPEC-ID 81) XPath Injection (CAPEC-ID 83) AJAX Fingerprinting (CAPEC-ID 85) Embedding Script (XSS) in HTTP Headers (CAPEC-ID 86) OS Command Injection (CAPEC-ID 88) Buffer Overflow in Local Command-Line Utilities (CAPEC-ID 9) XSS in IMG Tags (CAPEC-ID 91) XML Parser Attack (CAPEC-ID 99)