UBports Ubuntu Touch 16.04 allows the screen-unlock passcode to be used for a privileged shell via Sudo. This passcode is only four digits, far below typical length/complexity for a user accounts password. NOTE: a third party states The described attack cannot be executed as demonstrated.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ubuntu_touch | Ubports | 16.04 (including) | 16.04 (including) |