Vulnerability Description
A certain Qualcomm Innovation Center (QuIC) patch to the NativeDaemonConnector class in services/java/com/android/server/NativeDaemonConnector.java in Code Aurora Forum (CAF) releases of Android 4.1.x through 4.3.x enables debug logging, which allows attackers to obtain sensitive disk-encryption passwords via a logcat call.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Codeaurora | Android-Msm | 3.2.54 |
References
- https://www.codeaurora.org/projects/security-advisories/logging-potentially-sensVendor Advisory
- https://www.codeaurora.org/projects/security-advisories/logging-potentially-sensVendor Advisory
FAQ
What is CVE-2013-2599?
CVE-2013-2599 is a vulnerability with a CVSS score of 5.0 (MEDIUM). A certain Qualcomm Innovation Center (QuIC) patch to the NativeDaemonConnector class in services/java/com/android/server/NativeDaemonConnector.java in Code Aurora Forum (CAF) releases of Android 4.1.x...
How severe is CVE-2013-2599?
CVE-2013-2599 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2013-2599?
Check the references section above for vendor advisories and patch information. Affected products include: Codeaurora Android-Msm.