10
CVSSv2

CVE-2013-6774

Published: 31/03/2014 Updated: 10/11/2015
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Untrusted search path vulnerability in the ChainsDD Superuser package 3.1.3 for Android 4.2.x and previous versions, CyanogenMod/ClockWorkMod/Koush Superuser package 1.0.2.1 for Android 4.2.x and previous versions, and Chainfire SuperSU package prior to 1.69 for Android 4.2.x and previous versions allows malicious users to load an arbitrary .jar file and gain privileges via a crafted BOOTCLASSPATH environment variable for a /system/xbin/su process. NOTE: another researcher was unable to reproduce this with ChainsDD Superuser.

Vulnerable Product Search on Vulmon Subscribe to Product

chainfire supersu 1.69

androidsu chainsdd_superuser 3.1.3

koushik_dutta superuser 1.0.2.1

Exploits

Vulnerable releases of several common Android Superuser packages may allow malicious Android applications to execute arbitrary commands as root without notifying the device owner This advisoriy documents PATH and BOOTCLASSPATH vulnerabilities ...