10
CVSSv2

CVE-2013-6775

Published: 31/03/2014 Updated: 31/03/2014
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

The Chainfire SuperSU package prior to 1.69 for Android allows malicious users to gain privileges via the (1) backtick or (2) $() type of shell metacharacters in the -c option to /system/xbin/su.

Vulnerable Product Search on Vulmon Subscribe to Product

chainfire supersu 1.69

Exploits

Vulnerable releases of two common Android Superuser packages may allow malicious Android applications to execute arbitrary commands as root These issues are due to a shell character escape vulnerability ...