CVE Vulnerabilities

CVE-2013-6770

Published: Mar 31, 2014 | Modified: Apr 03, 2014
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.6 HIGH
AV:N/AC:H/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

The CyanogenMod/ClockWorkMod/Koush Superuser package 1.0.2.1 for Android 4.3 and 4.4 does not properly restrict the set of users who can execute /system/xbin/su with the –daemon option, which allows attackers to gain privileges by leveraging ADB shell access and a certain Linux UID, and then creating a Trojan horse script.

Affected Software

Name Vendor Start Version End Version
Superuser Koushik_dutta 1.0.2.1 (including) 1.0.2.1 (including)

References