A certain Qualcomm Innovation Center (QuIC) patch to the NativeDaemonConnector class in services/java/com/android/server/NativeDaemonConnector.java in Code Aurora Forum (CAF) releases of Android 4.1.x through 4.3.x enables debug logging, which allows attackers to obtain sensitive disk-encryption passwords via a logcat call.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2014-08-31 03:55
Updated : 2015-11-10 11:09
NVD link : CVE-2013-2599
Mitre link : CVE-2013-2599
JSON object : View
CWE
Products Affected
codeaurora
- android-msm