PT-2014-3029 · Google · Android
Published
2014-08-31
·
Updated
2014-09-02
·
CVE-2013-6124
CVSS v2.0
3.3
Low
| Vector | AV:L/AC:M/Au:N/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Android versions 4.1.x through 4.4.x
Description
The issue allows local users to modify file metadata via a symlink attack on a file accessed by a (1) chown or (2) chmod command. This can be demonstrated by changing the permissions of an arbitrary file via an attack on the sensor-settings file.
Recommendations
For Android versions 4.1.x through 4.4.x, consider restricting access to the sensor-settings file to prevent symlink attacks until a patch is available. As a temporary workaround, avoid using the chown or chmod commands on files that can be accessed by local users.
Fix
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Android