Lucene search

K
androidJon SawyerANDROID:QUALCOMM_CHOWN_INIT_SCRIPTS
HistoryFeb 19, 2014 - 12:00 a.m.

Qualcomm chown init scripts

2014-02-1900:00:00
Jon Sawyer
www.androidvulnerabilities.org
17

0.0004 Low

EPSS

Percentile

5.1%

Insecure owner/permission changes in init shell scripts (CVE-2013-6124): During the device start-up phase, several init shell scripts are executed with root privileges to configure various aspects of the system. During this process, standard toolchain commands such as chown or chmod are used to, e.g., change the owner of the sensor settings file to the system user. As these commands follow symbolic links (symlinks), an attacker with write access to these resources is able to conduct symlink attacks and thus change for example the owner of an arbitrary file to system. This flaw can be used to, e.g., elevate privileges.

0.0004 Low

EPSS

Percentile

5.1%

Related for ANDROID:QUALCOMM_CHOWN_INIT_SCRIPTS