PT-2020-7740 · Google · Android

Imre Rad

·

Published

2020-02-20

·

Updated

2020-02-25

·

CVE-2014-7951

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Android versions 4.0.4
Description A directory traversal issue exists in the Android debug bridge, allowing physically proximate attackers with a direct connection to the target device to write to arbitrary system-owned files by using a .. (dot dot) in the tar archive headers.
Recommendations For Android version 4.0.4, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-7951

Affected Products

Android