7.2
CVSSv2

CVE-2011-1823

Published: 09/06/2011 Updated: 07/11/2023
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 642
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

The vold volume manager daemon on Android 3.0 and 2.x prior to 2.3.4 trusts messages that are received from a PF_NETLINK socket, which allows local users to execute arbitrary code and gain root privileges via a negative index that bypasses a maximum-only signed integer check in the DirectVolume::handlePartitionAdded method, which triggers memory corruption, as demonstrated by Gingerbreak.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

google android 2.2.3

google android 2.1

google android 2.3

google android 2.3.3

google android 3.0

google android 2.3.1

google android 2.2.1

google android 2.2.2

google android 2.2

google android 2.3.2