CVE-2011-1350: Infoleak
Published Feb 5, 2013
·Updated
The PowerVR SGX driver in Android before 2.3.6 allows attackers to obtain potentially sensitive information from kernel stack memory via an application that uses a crafted length parameter in a request to the pvrsrvkm device.
Affected Software
17 affected components
Google Android=2.2.3
Google Android=2.0.1
Google Android=1.0
Google Android=1.6
Google Android=2.1
Google Android=2.3.3
Google Android=2.0
Google Android=2.3.1
Google Android<=2.3.5
Google Android=1.5
Google Android=2.2.1
Google Android=2.2.2
Google Android=2.2
Google Android=2.3.4
Google Android=1.1
Google Android=2.3.2
Google Android=2.3
Event History
Feb 5, 2013
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-1350?
CVE-2011-1350 has a medium severity level as it can expose sensitive information from kernel stack memory.
2
How do I fix CVE-2011-1350?
To mitigate CVE-2011-1350, update your Android device to version 2.3.6 or later.
3
Who is affected by CVE-2011-1350?
CVE-2011-1350 affects users with Android versions ranging from 1.0 to 2.3.5.
4
What type of attack does CVE-2011-1350 enable?
CVE-2011-1350 allows attackers to obtain sensitive information through crafted requests to the pvrsrvkm device.
5
Is CVE-2011-1350 a remote vulnerability?
CVE-2011-1350 is not considered a remote vulnerability, as it requires a local application to exploit the flaw.