Release date:
Updated on:
Affected Systems:
Amazon Kindle Touch
Description:
--------------------------------------------------------------------------------
Bugtraq id: 54977
Cve id: CVE-2012-4248, CVE-2012-4249
Amazon Kindle Touch is a powerful player audio/video playback capability, professional e-book reading function, and supports multiple formats of e-books.
Amazon Kindle Touch 5.1.2 and earlier versions have Command Execution Vulnerabilities and code execution vulnerabilities. Attackers can exploit these vulnerabilities to execute arbitrary commands and code with root privileges.
<* Source: eureka
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Amazon
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.amazon.com/Kindle-Touch-e-Reader-Touch-Screen-Wi-Fi-Special-Offers/dp/B005890G8Y