9.3

CVE-2013-4787

Android 1.6 Donut through 4.2 Jelly Bean does not properly check cryptographic signatures for applications, which allows attackers to execute arbitrary code via an application package file (APK) that is modified in a way that does not violate the cryptographic signature, probably involving multiple entries in a Zip file with the same name in which one entry is validated but the other entry is installed, aka Android security bug 8219321 and the "Master Key" vulnerability.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Google ≫ Android Version 1.6
Google ≫ Android Version 2.0
Google ≫ Android Version 2.0.1
Google ≫ Android Version 2.1
Google ≫ Android Version 2.2
Google ≫ Android Version 2.2 Update rev1
Google ≫ Android Version 2.2.1
Google ≫ Android Version 2.2.2
Google ≫ Android Version 2.2.3
Google ≫ Android Version 2.3
Google ≫ Android Version 2.3 Update rev1
Google ≫ Android Version 2.3.1
Google ≫ Android Version 2.3.2
Google ≫ Android Version 2.3.3
Google ≫ Android Version 2.3.4
Google ≫ Android Version 2.3.5
Google ≫ Android Version 2.3.6
Google ≫ Android Version 2.3.7
Google ≫ Android Version 3.0
Google ≫ Android Version 3.1
Google ≫ Android Version 3.2
Google ≫ Android Version 3.2.1
Google ≫ Android Version 3.2.2
Google ≫ Android Version 3.2.4
Google ≫ Android Version 3.2.6
Google ≫ Android Version 4.0
Google ≫ Android Version 4.0.1
Google ≫ Android Version 4.0.2
Google ≫ Android Version 4.0.3
Google ≫ Android Version 4.0.4
Google ≫ Android Version 4.1
Google ≫ Android Version 4.1.2
Google ≫ Android Version 4.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 58.92% 0.99
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://bluebox.com/corporate-blog/bluebox-uncovers-android-master-key/
http://review.cyanogenmod.org/#/c/45251/
http://www.osvdb.org/94773
http://www.securityfocus.com/bid/60952
http://www.zdnet.com/google-releases-fix-to-oems-for-blue-security-android-security-hole-7000017782/
https://jira.cyanogenmod.org/browse/CYAN-1602
https://plus.google.com/113331808607528811927/posts/GxDA6111vYy