7

CVE-2013-3685

Exploit
A Privilege Escalation Vulnerability exists in Sprite Software Spritebud 1.3.24 and 1.3.28 and Backup 2.5.4105 and 2.5.4108 on LG Android smartphones due to a race condition in the spritebud daemon, which could let a local malicious user obtain root privileges.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SpritesoftwareSpritebackup Version2.5.4105
   LgE971 Version-
   LgE973 Version-
   LgE975 Version-
   LgE975k Version-
   LgE975t Version-
   LgE976 Version-
   LgE977 Version-
   LgF100k Version-
   LgF100l Version-
   LgF100s Version-
   LgF120k Version-
   LgF120l Version-
   LgF120s Version-
   LgF160k Version-
   LgF160l Version-
   LgF160lv Version-
   LgF160s Version-
   LgF180k Version-
   LgF180l Version-
   LgF180s Version-
   LgF200k Version-
   LgF200l Version-
   LgF200s Version-
   LgF240k Version-
   LgF240l Version-
   LgF240s Version-
   LgF260k Version-
   LgF260l Version-
   LgF260s Version-
   LgL21 Version-
   LgLg870 Version-
   LgLs860 Version-
   LgLs970 Version-
   LgP760 Version-
   LgP769 Version-
   LgP780 Version-
   LgP875 Version-
   LgP875h Version-
   LgP880 Version-
   LgP940 Version-
   LgSu540 Version-
   LgSu870 Version-
   LgUs780 Version-
SpritesoftwareSpritebackup Version2.5.4108
   LgE971 Version-
   LgE973 Version-
   LgE975 Version-
   LgE975k Version-
   LgE975t Version-
   LgE976 Version-
   LgE977 Version-
   LgF100k Version-
   LgF100l Version-
   LgF100s Version-
   LgF120k Version-
   LgF120l Version-
   LgF120s Version-
   LgF160k Version-
   LgF160l Version-
   LgF160lv Version-
   LgF160s Version-
   LgF180k Version-
   LgF180l Version-
   LgF180s Version-
   LgF200k Version-
   LgF200l Version-
   LgF200s Version-
   LgF240k Version-
   LgF240l Version-
   LgF240s Version-
   LgF260k Version-
   LgF260l Version-
   LgF260s Version-
   LgL21 Version-
   LgLg870 Version-
   LgLs860 Version-
   LgLs970 Version-
   LgP760 Version-
   LgP769 Version-
   LgP780 Version-
   LgP875 Version-
   LgP875h Version-
   LgP880 Version-
   LgP940 Version-
   LgSu540 Version-
   LgSu870 Version-
   LgUs780 Version-
SpritesoftwareSpritebud Version1.3.24
   LgE971 Version-
   LgE973 Version-
   LgE975 Version-
   LgE975k Version-
   LgE975t Version-
   LgE976 Version-
   LgE977 Version-
   LgF100k Version-
   LgF100l Version-
   LgF100s Version-
   LgF120k Version-
   LgF120l Version-
   LgF120s Version-
   LgF160k Version-
   LgF160l Version-
   LgF160lv Version-
   LgF160s Version-
   LgF180k Version-
   LgF180l Version-
   LgF180s Version-
   LgF200k Version-
   LgF200l Version-
   LgF200s Version-
   LgF240k Version-
   LgF240l Version-
   LgF240s Version-
   LgF260k Version-
   LgF260l Version-
   LgF260s Version-
   LgL21 Version-
   LgLg870 Version-
   LgLs860 Version-
   LgLs970 Version-
   LgP760 Version-
   LgP769 Version-
   LgP780 Version-
   LgP875 Version-
   LgP875h Version-
   LgP880 Version-
   LgP940 Version-
   LgSu540 Version-
   LgSu870 Version-
   LgUs780 Version-
SpritesoftwareSpritebud Version1.3.28
   LgE971 Version-
   LgE973 Version-
   LgE975 Version-
   LgE975k Version-
   LgE975t Version-
   LgE976 Version-
   LgE977 Version-
   LgF100k Version-
   LgF100l Version-
   LgF100s Version-
   LgF120k Version-
   LgF120l Version-
   LgF120s Version-
   LgF160k Version-
   LgF160l Version-
   LgF160lv Version-
   LgF160s Version-
   LgF180k Version-
   LgF180l Version-
   LgF180s Version-
   LgF200k Version-
   LgF200l Version-
   LgF200s Version-
   LgF240k Version-
   LgF240l Version-
   LgF240s Version-
   LgF260k Version-
   LgF260l Version-
   LgF260s Version-
   LgL21 Version-
   LgLg870 Version-
   LgLs860 Version-
   LgLs970 Version-
   LgP760 Version-
   LgP769 Version-
   LgP780 Version-
   LgP875 Version-
   LgP875h Version-
   LgP880 Version-
   LgP940 Version-
   LgSu540 Version-
   LgSu870 Version-
   LgUs780 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.08% 0.202
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7 1 5.9
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 6.9 3.4 10
AV:L/AC:M/Au:N/C:C/I:C/A:C
CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.