CVE-2013-2598
Last modified
CVE-2013-2598 is a vulnerability of currently unknown severity. app/aboot/aboot.c in the Little Kernel (LK) bootloader, as distributed with Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to overwrite signature-verification code via crafted boot-image load-destination header values that specify memory locations within bootloader memory.. EPSS estimates a 0.31% chance of exploitation in the next 30 days.
Description
app/aboot/aboot.c in the Little Kernel (LK) bootloader, as distributed with Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to overwrite signature-verification code via crafted boot-image load-destination header values that specify memory locations within bootloader memory.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Codeaurora | Android-Msm | 2.6.29 | — |
| Codeaurora | Android-Msm | 3.2.54 | — |
| Codeaurora | Android-Msm | 3.2.55 | — |
| Codeaurora | Android-Msm | 3.2.56 | — |
| Codeaurora | Android-Msm | 3.2.57 | — |
| Codeaurora | Android-Msm | 3.2.58 | — |
| Codeaurora | Android-Msm | 3.2.59 | — |
| Codeaurora | Android-Msm | 3.2.60 | — |
| Codeaurora | Android-Msm | 3.2.61 | — |
| Codeaurora | Android-Msm | 3.2.62 | — |
| Codeaurora | Android-Msm | 3.4.72 | — |
| Codeaurora | Android-Msm | 3.4.73 | — |
| Codeaurora | Android-Msm | 3.4.74 | — |
| Codeaurora | Android-Msm | 3.4.75 | — |
| Codeaurora | Android-Msm | 3.4.76 | — |
| Codeaurora | Android-Msm | 3.4.77 | — |
| Codeaurora | Android-Msm | 3.4.78 | — |
| Codeaurora | Android-Msm | 3.4.79 | — |
| Codeaurora | Android-Msm | 3.4.80 | — |
| Codeaurora | Android-Msm | 3.4.81 | — |
| Codeaurora | Android-Msm | 3.4.82 | — |
| Codeaurora | Android-Msm | 3.4.83 | — |
| Codeaurora | Android-Msm | 3.4.84 | — |
| Codeaurora | Android-Msm | 3.4.85 | — |
| Codeaurora | Android-Msm | 3.4.86 | — |
| Codeaurora | Android-Msm | 3.4.87 | — |
| Codeaurora | Android-Msm | 3.4.88 | — |
| Codeaurora | Android-Msm | 3.4.89 | — |
| Codeaurora | Android-Msm | 3.4.90 | — |
| Codeaurora | Android-Msm | 3.4.91 | — |
| Codeaurora | Android-Msm | 3.4.92 | — |
| Codeaurora | Android-Msm | 3.4.93 | — |
| Codeaurora | Android-Msm | 3.4.94 | — |
| Codeaurora | Android-Msm | 3.4.95 | — |
| Codeaurora | Android-Msm | 3.4.96 | — |
| Codeaurora | Android-Msm | 3.4.97 | — |
| Codeaurora | Android-Msm | 3.4.98 | — |
| Codeaurora | Android-Msm | 3.4.99 | — |
| Codeaurora | Android-Msm | 3.4.100 | — |
| Codeaurora | Android-Msm | 3.4.101 | — |
| Codeaurora | Android-Msm | 3.4.102 | — |
| Codeaurora | Android-Msm | 3.4.103 | — |
| Codeaurora | Android-Msm | 3.10 | — |
| Codeaurora | Android-Msm | 3.10.22 | — |
| Codeaurora | Android-Msm | 3.10.23 | — |
| Codeaurora | Android-Msm | 3.10.24 | — |
| Codeaurora | Android-Msm | 3.10.25 | — |
| Codeaurora | Android-Msm | 3.10.26 | — |
| Codeaurora | Android-Msm | 3.10.27 | — |
| Codeaurora | Android-Msm | 3.10.28 | — |
Showing 50 of 141 affected configurations. See NVD for the full list.
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2013-2598?
How severe is CVE-2013-2598?
How do I fix CVE-2013-2598?
Are you affected by CVE-2013-2598?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
