PT-2019-11516 · Lineageos · Lineageos

Zifnab06

·

Published

2019-07-23

·

Updated

2020-08-24

·

CVE-2019-1010221

CVSS v3.1

6.8

Medium

VectorAV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: LineageOS versions 16.0 and earlier
Description: The issue concerns incorrect access control. It allows an attacker with physical access to exploit the adb shell component by setting a specific property, enabling them to restart adb as root. This can be achieved by running the command adb shell setprop service.adb.root 1 in a normal adb shell session when adb is enabled.
Recommendations: For LineageOS versions 16.0 and earlier, consider disabling adb access when not needed to minimize the risk of exploitation. As a temporary workaround, restrict physical access to devices until a patch is applied. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2019-1010221

Affected Products

Lineageos