10

CVE-2013-6774

Exploit

Untrusted search path vulnerability in the ChainsDD Superuser package 3.1.3 for Android 4.2.x and earlier, CyanogenMod/ClockWorkMod/Koush Superuser package 1.0.2.1 for Android 4.2.x and earlier, and Chainfire SuperSU package before 1.69 for Android 4.2.x and earlier allows attackers to load an arbitrary .jar file and gain privileges via a crafted BOOTCLASSPATH environment variable for a /system/xbin/su process.  NOTE: another researcher was unable to reproduce this with ChainsDD Superuser.

Data is provided by the National Vulnerability Database (NVD)
ChainfireSupersu Version1.69 SwPlatformandroid
   GoogleAndroid Version1.0
   GoogleAndroid Version1.1
   GoogleAndroid Version1.5
   GoogleAndroid Version1.6
   GoogleAndroid Version2.0
   GoogleAndroid Version2.0.1
   GoogleAndroid Version2.1
   GoogleAndroid Version2.2
   GoogleAndroid Version2.2 Updaterev1
   GoogleAndroid Version2.2.1
   GoogleAndroid Version2.2.2
   GoogleAndroid Version2.2.3
   GoogleAndroid Version2.3
   GoogleAndroid Version2.3 Updaterev1
   GoogleAndroid Version2.3.1
   GoogleAndroid Version2.3.2
   GoogleAndroid Version2.3.3
   GoogleAndroid Version2.3.4
   GoogleAndroid Version2.3.5
   GoogleAndroid Version2.3.6
   GoogleAndroid Version2.3.7
   GoogleAndroid Version3.0
   GoogleAndroid Version3.1
   GoogleAndroid Version3.2
   GoogleAndroid Version3.2.1
   GoogleAndroid Version3.2.2
   GoogleAndroid Version3.2.4
   GoogleAndroid Version3.2.6
   GoogleAndroid Version4.0
   GoogleAndroid Version4.0.1
   GoogleAndroid Version4.0.2
   GoogleAndroid Version4.0.3
   GoogleAndroid Version4.0.4
   GoogleAndroid Version4.1
   GoogleAndroid Version4.1.2
   GoogleAndroid Version4.2
   GoogleAndroid Version4.2.1
   GoogleAndroid Version4.2.2
AndroidsuChainsdd Superuser Version3.1.3 SwPlatformandroid
   GoogleAndroid Version1.0
   GoogleAndroid Version1.1
   GoogleAndroid Version1.5
   GoogleAndroid Version1.6
   GoogleAndroid Version2.0
   GoogleAndroid Version2.0.1
   GoogleAndroid Version2.1
   GoogleAndroid Version2.2
   GoogleAndroid Version2.2 Updaterev1
   GoogleAndroid Version2.2.1
   GoogleAndroid Version2.2.2
   GoogleAndroid Version2.2.3
   GoogleAndroid Version2.3
   GoogleAndroid Version2.3 Updaterev1
   GoogleAndroid Version2.3.1
   GoogleAndroid Version2.3.2
   GoogleAndroid Version2.3.3
   GoogleAndroid Version2.3.4
   GoogleAndroid Version2.3.5
   GoogleAndroid Version2.3.6
   GoogleAndroid Version2.3.7
   GoogleAndroid Version3.0
   GoogleAndroid Version3.1
   GoogleAndroid Version3.2
   GoogleAndroid Version3.2.1
   GoogleAndroid Version3.2.2
   GoogleAndroid Version3.2.4
   GoogleAndroid Version3.2.6
   GoogleAndroid Version4.0
   GoogleAndroid Version4.0.1
   GoogleAndroid Version4.0.2
   GoogleAndroid Version4.0.3
   GoogleAndroid Version4.0.4
   GoogleAndroid Version4.1
   GoogleAndroid Version4.1.2
   GoogleAndroid Version4.2
   GoogleAndroid Version4.2.1
   GoogleAndroid Version4.2.2
Koushik DuttaSuperuser Version1.0.2.1
   GoogleAndroid Version1.0
   GoogleAndroid Version1.1
   GoogleAndroid Version1.5
   GoogleAndroid Version1.6
   GoogleAndroid Version2.0
   GoogleAndroid Version2.0.1
   GoogleAndroid Version2.1
   GoogleAndroid Version2.2
   GoogleAndroid Version2.2 Updaterev1
   GoogleAndroid Version2.2.1
   GoogleAndroid Version2.2.2
   GoogleAndroid Version2.2.3
   GoogleAndroid Version2.3
   GoogleAndroid Version2.3 Updaterev1
   GoogleAndroid Version2.3.1
   GoogleAndroid Version2.3.2
   GoogleAndroid Version2.3.3
   GoogleAndroid Version2.3.4
   GoogleAndroid Version2.3.5
   GoogleAndroid Version2.3.6
   GoogleAndroid Version2.3.7
   GoogleAndroid Version3.0
   GoogleAndroid Version3.1
   GoogleAndroid Version3.2
   GoogleAndroid Version3.2.1
   GoogleAndroid Version3.2.2
   GoogleAndroid Version3.2.4
   GoogleAndroid Version3.2.6
   GoogleAndroid Version4.0
   GoogleAndroid Version4.0.1
   GoogleAndroid Version4.0.2
   GoogleAndroid Version4.0.3
   GoogleAndroid Version4.0.4
   GoogleAndroid Version4.1
   GoogleAndroid Version4.1.2
   GoogleAndroid Version4.2
   GoogleAndroid Version4.2.1
   GoogleAndroid Version4.2.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.37% 0.559
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C