Exploitation Summary
EIP tracks 1 public exploit for CVE-2016-8477. PoCs published by derrekr.
AI-analyzed exploit summary This PoC demonstrates an information leak vulnerability in the Qualcomm MSM camera driver by exploiting an uninitialized kernel memory disclosure via the VIDIOC_MSM_EEPROM_CFG ioctl. The code reads uninitialized data from the kernel's eeprom_name buffer, which may contain sensitive information.
Description
An information disclosure vulnerability in the Qualcomm camera driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-32720522. References: QC-CR#1090007.
Exploits (1)
This PoC demonstrates an information leak vulnerability in the Qualcomm MSM camera driver by exploiting an uninitialized kernel memory disclosure via the VIDIOC_MSM_EEPROM_CFG ioctl. The code reads uninitialized data from the kernel's eeprom_name buffer, which may contain sensitive information.
References (6)
Scores
CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N