CVE-2014-0973
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The image_verify function in platform/msm_shared/image_verify.c in the Little Kernel (LK) bootloader, as distributed with Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, does not check whether a certain digest size is consistent with the RSA_public_decrypt API specification, which makes it easier for attackers to bypass boot-image authentication requirements via trailing data.
La función image_verify en platform/msm_shared/image_verify.c en el bootloader Little Kernel (LK), distribuido con las contribuciones Android Qualcomm Innovation Center (QuIC) para dispositivos MSM y otros productoss, no comprueba si cierto tamaño digest es consistente con la especificación RSA_public_decrypt API, lo que facilita a atacantes evadir los requisitos de la autenticación para arranque de imágenes a través de datos finales.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2014-01-07 CVE Reserved
- 2014-08-25 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-287: Improper Authentication
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://source.android.com/security/bulletin/2016-07-01.html | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.codeaurora.org/projects/security-advisories/incomplete-signature-parsing-during-boot-image-authentication-leads-to-signature-forgery-cve-2014-0973 | 2016-07-13 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Little Kernel Project Search vendor "Little Kernel Project" | Little Kernel Bootloader Search vendor "Little Kernel Project" for product "Little Kernel Bootloader" | - | android |
Affected
|