Vulnerability Description
app/aboot/aboot.c in the Little Kernel (LK) bootloader, as distributed with Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to overwrite signature-verification code via crafted boot-image load-destination header values that specify memory locations within bootloader memory.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Codeaurora | Android-Msm | 2.6.29 |
Related Weaknesses (CWE)
References
- https://www.codeaurora.org/projects/security-advisories/loading-image-data-memorVendor Advisory
- https://www.codeaurora.org/projects/security-advisories/loading-image-data-memorVendor Advisory
FAQ
What is CVE-2013-2598?
CVE-2013-2598 is a vulnerability with a CVSS score of 6.6 (MEDIUM). app/aboot/aboot.c in the Little Kernel (LK) bootloader, as distributed with Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to overwrite si...
How severe is CVE-2013-2598?
CVE-2013-2598 has been rated MEDIUM with a CVSS base score of 6.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2013-2598?
Check the references section above for vendor advisories and patch information. Affected products include: Codeaurora Android-Msm.