PT-2014-3029 · Google · Android

Published

2014-08-31

·

Updated

2014-09-02

·

CVE-2013-6124

CVSS v2.0

3.3

Low

VectorAV:L/AC:M/Au:N/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions Android versions 4.1.x through 4.4.x
Description The issue allows local users to modify file metadata via a symlink attack on a file accessed by a (1) chown or (2) chmod command. This can be demonstrated by changing the permissions of an arbitrary file via an attack on the sensor-settings file.
Recommendations For Android versions 4.1.x through 4.4.x, consider restricting access to the sensor-settings file to prevent symlink attacks until a patch is available. As a temporary workaround, avoid using the chown or chmod commands on files that can be accessed by local users.

Fix

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-6124

Affected Products

Android