CVE-2012-4249

Amazon Kindle Touch - OS Command Injection via LIPC Property Manipulation

Title source: llm
STIX 2.1

Description

The Amazon Lab126 com.lab126.system sendEvent implementation on the Kindle Touch before 5.1.2 allows context-dependent attackers to execute arbitrary commands via shell metacharacters in a string, as demonstrated by using lipc-set-prop to set an LIPC property, a different vulnerability than CVE-2012-4248.

References (3)

Core 3
Core References
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/122656
US Government Resource x_refsource_confirm
http://www.kb.cert.org/vuls/id/MORO-8WKGBN

Scores

EPSS 0.0290
EPSS Percentile 86.5%

Details

CWE
CWE-94
Status published
Products (2)
amazon/kindle_touch 5.1.0
amazon/kindle_touch 5.1.1
Published Aug 12, 2012
Tracked Since Feb 18, 2026