CVE-2012-2980

UnknownEPSS 1.76%

Last modified

CVE-2012-2980 is a vulnerability of currently unknown severity. The Samsung and HTC onTouchEvent method implementation for Android on the T-Mobile myTouch 3G Slide, HTC Merge, Sprint EVO Shift 4G, HTC ChaCha, AT&T Status, HTC Desire Z, T-Mobile G2, T-Mobile myTouch 4G Slide, and Samsung Galaxy S stores touch coordinates in the dmesg buffer, which allows remote attackers to obtain sensitive information via a crafted application, as demonstrated by PIN numbers, telephone numbers, and text messages.. EPSS estimates a 1.76% chance of exploitation in the next 30 days.

Description

The Samsung and HTC onTouchEvent method implementation for Android on the T-Mobile myTouch 3G Slide, HTC Merge, Sprint EVO Shift 4G, HTC ChaCha, AT&T Status, HTC Desire Z, T-Mobile G2, T-Mobile myTouch 4G Slide, and Samsung Galaxy S stores touch coordinates in the dmesg buffer, which allows remote attackers to obtain sensitive information via a crafted application, as demonstrated by PIN numbers, telephone numbers, and text messages.

Metrics

CVSS 3.0
/10
EPSS Probability
1.76%

75.1th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
AttStatusAll versions
HtcChachaAll versions
HtcDesireAll versions
HtcMergeAll versions
SamsungGalaxy SAll versions
SprintEvo Shift 4gAll versions
T-MobileG2All versions
T-MobileMytouch 3g SlideAll versions
T-MobileMytouch 4g SlideAll versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2012-2980?
The Samsung and HTC onTouchEvent method implementation for Android on the T-Mobile myTouch 3G Slide, HTC Merge, Sprint EVO Shift 4G, HTC ChaCha, AT&T Status, HTC Desire Z, T-Mobile G2, T-Mobile myTouch 4G Slide, and Samsung Galaxy S stores touch coordinates in the dmesg buffer, which allows remote attackers to obtain sensitive information via a crafted application, as demonstrated by PIN numbers, telephone numbers, and text messages.
How severe is CVE-2012-2980?
Severity scoring for CVE-2012-2980 is pending analysis. The EPSS model estimates a 1.76% probability of exploitation in the next 30 days.
How do I fix CVE-2012-2980?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2012-2980?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST