CVE-2011-1823

The vold volume manager daemon on Android 3.0 and 2.x before 2.3.4 trusts messages that are received from a PF_NETLINK socket, which allows local users to execute arbitrary code and gain root privileges via a negative index that bypasses a maximum-only signed integer check in the DirectVolume::handlePartitionAdded method, which triggers memory corruption, as demonstrated by Gingerbreak.
References
Link Resource
http://android.git.kernel.org/?p=platform/system/core.git%3Ba=commit%3Bh=b620a0b1c7ae486e979826200e8e441605b0a5d6 Broken Link
http://android.git.kernel.org/?p=platform/system/netd.git%3Ba=commit%3Bh=79b579c92afc08ab12c0a5788d61f2dd2934836f Broken Link
http://android.git.kernel.org/?p=platform/system/vold.git%3Ba=commit%3Bh=c51920c82463b240e2be0430849837d6fdc5352e Broken Link
http://androidcommunity.com/gingerbreak-root-for-gingerbread-app-20110421/ Broken Link
http://c-skills.blogspot.com/2011/04/yummy-yummy-gingerbreak.html Exploit Issue Tracking
http://forum.xda-developers.com/showthread.php?t=1044765 Exploit Issue Tracking
http://www.androidpolice.com/2011/05/03/google-patches-gingerbreak-exploit-but-dont-worry-we-still-have-root-for-now/ Press/Media Coverage
http://xorl.wordpress.com/2011/04/28/android-vold-mpartminors-signedness-issue/ Exploit
https://exchange.xforce.ibmcloud.com/vulnerabilities/67977 Third Party Advisory VDB Entry
http://android.git.kernel.org/?p=platform/system/core.git%3Ba=commit%3Bh=b620a0b1c7ae486e979826200e8e441605b0a5d6 Broken Link
http://android.git.kernel.org/?p=platform/system/netd.git%3Ba=commit%3Bh=79b579c92afc08ab12c0a5788d61f2dd2934836f Broken Link
http://android.git.kernel.org/?p=platform/system/vold.git%3Ba=commit%3Bh=c51920c82463b240e2be0430849837d6fdc5352e Broken Link
http://androidcommunity.com/gingerbreak-root-for-gingerbread-app-20110421/ Broken Link
http://c-skills.blogspot.com/2011/04/yummy-yummy-gingerbreak.html Exploit Issue Tracking
http://forum.xda-developers.com/showthread.php?t=1044765 Exploit Issue Tracking
http://www.androidpolice.com/2011/05/03/google-patches-gingerbreak-exploit-but-dont-worry-we-still-have-root-for-now/ Press/Media Coverage
http://xorl.wordpress.com/2011/04/28/android-vold-mpartminors-signedness-issue/ Exploit
https://exchange.xforce.ibmcloud.com/vulnerabilities/67977 Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:google:android:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:3.0:*:*:*:*:*:*:*

History

21 Nov 2024, 01:27

Type Values Removed Values Added
References () http://android.git.kernel.org/?p=platform/system/core.git%3Ba=commit%3Bh=b620a0b1c7ae486e979826200e8e441605b0a5d6 - Broken Link () http://android.git.kernel.org/?p=platform/system/core.git%3Ba=commit%3Bh=b620a0b1c7ae486e979826200e8e441605b0a5d6 - Broken Link
References () http://android.git.kernel.org/?p=platform/system/netd.git%3Ba=commit%3Bh=79b579c92afc08ab12c0a5788d61f2dd2934836f - Broken Link () http://android.git.kernel.org/?p=platform/system/netd.git%3Ba=commit%3Bh=79b579c92afc08ab12c0a5788d61f2dd2934836f - Broken Link
References () http://android.git.kernel.org/?p=platform/system/vold.git%3Ba=commit%3Bh=c51920c82463b240e2be0430849837d6fdc5352e - Broken Link () http://android.git.kernel.org/?p=platform/system/vold.git%3Ba=commit%3Bh=c51920c82463b240e2be0430849837d6fdc5352e - Broken Link
References () http://androidcommunity.com/gingerbreak-root-for-gingerbread-app-20110421/ - Broken Link () http://androidcommunity.com/gingerbreak-root-for-gingerbread-app-20110421/ - Broken Link
References () http://c-skills.blogspot.com/2011/04/yummy-yummy-gingerbreak.html - Exploit, Issue Tracking () http://c-skills.blogspot.com/2011/04/yummy-yummy-gingerbreak.html - Exploit, Issue Tracking
References () http://forum.xda-developers.com/showthread.php?t=1044765 - Exploit, Issue Tracking () http://forum.xda-developers.com/showthread.php?t=1044765 - Exploit, Issue Tracking
References () http://www.androidpolice.com/2011/05/03/google-patches-gingerbreak-exploit-but-dont-worry-we-still-have-root-for-now/ - Press/Media Coverage () http://www.androidpolice.com/2011/05/03/google-patches-gingerbreak-exploit-but-dont-worry-we-still-have-root-for-now/ - Press/Media Coverage
References () http://xorl.wordpress.com/2011/04/28/android-vold-mpartminors-signedness-issue/ - Exploit () http://xorl.wordpress.com/2011/04/28/android-vold-mpartminors-signedness-issue/ - Exploit
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/67977 - Third Party Advisory, VDB Entry () https://exchange.xforce.ibmcloud.com/vulnerabilities/67977 - Third Party Advisory, VDB Entry

28 Jun 2024, 14:02

Type Values Removed Values Added
References () http://android.git.kernel.org/?p=platform/system/core.git%3Ba=commit%3Bh=b620a0b1c7ae486e979826200e8e441605b0a5d6 - () http://android.git.kernel.org/?p=platform/system/core.git%3Ba=commit%3Bh=b620a0b1c7ae486e979826200e8e441605b0a5d6 - Broken Link
References () http://android.git.kernel.org/?p=platform/system/netd.git%3Ba=commit%3Bh=79b579c92afc08ab12c0a5788d61f2dd2934836f - () http://android.git.kernel.org/?p=platform/system/netd.git%3Ba=commit%3Bh=79b579c92afc08ab12c0a5788d61f2dd2934836f - Broken Link
References () http://android.git.kernel.org/?p=platform/system/vold.git%3Ba=commit%3Bh=c51920c82463b240e2be0430849837d6fdc5352e - () http://android.git.kernel.org/?p=platform/system/vold.git%3Ba=commit%3Bh=c51920c82463b240e2be0430849837d6fdc5352e - Broken Link
References () http://androidcommunity.com/gingerbreak-root-for-gingerbread-app-20110421/ - () http://androidcommunity.com/gingerbreak-root-for-gingerbread-app-20110421/ - Broken Link
References () http://c-skills.blogspot.com/2011/04/yummy-yummy-gingerbreak.html - Exploit () http://c-skills.blogspot.com/2011/04/yummy-yummy-gingerbreak.html - Exploit, Issue Tracking
References () http://forum.xda-developers.com/showthread.php?t=1044765 - Exploit () http://forum.xda-developers.com/showthread.php?t=1044765 - Exploit, Issue Tracking
References () http://www.androidpolice.com/2011/05/03/google-patches-gingerbreak-exploit-but-dont-worry-we-still-have-root-for-now/ - () http://www.androidpolice.com/2011/05/03/google-patches-gingerbreak-exploit-but-dont-worry-we-still-have-root-for-now/ - Press/Media Coverage
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/67977 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/67977 - Third Party Advisory, VDB Entry
CVSS v2 : 7.2
v3 : unknown
v2 : 7.2
v3 : 7.8
CWE CWE-189 CWE-190
CPE cpe:2.3:o:google:android:2.3.1:*:*:*:*:*:*:*
cpe:2.3:o:google:android:2.2.3:*:*:*:*:*:*:*
cpe:2.3:o:google:android:2.1:*:*:*:*:*:*:*
cpe:2.3:o:google:android:2.3.2:*:*:*:*:*:*:*
cpe:2.3:o:google:android:2.2:*:*:*:*:*:*:*
cpe:2.3:o:google:android:2.2:rev1:*:*:*:*:*:*
cpe:2.3:o:google:android:2.3.3:*:*:*:*:*:*:*
cpe:2.3:o:google:android:2.2.2:*:*:*:*:*:*:*
cpe:2.3:o:google:android:2.2.1:*:*:*:*:*:*:*
cpe:2.3:o:google:android:2.3:rev1:*:*:*:*:*:*
cpe:2.3:o:google:android:*:*:*:*:*:*:*:*

07 Nov 2023, 02:07

Type Values Removed Values Added
References
  • {'url': 'http://android.git.kernel.org/?p=platform/system/vold.git;a=commit;h=c51920c82463b240e2be0430849837d6fdc5352e', 'name': 'http://android.git.kernel.org/?p=platform/system/vold.git;a=commit;h=c51920c82463b240e2be0430849837d6fdc5352e', 'tags': [], 'refsource': 'CONFIRM'}
  • {'url': 'http://android.git.kernel.org/?p=platform/system/core.git;a=commit;h=b620a0b1c7ae486e979826200e8e441605b0a5d6', 'name': 'http://android.git.kernel.org/?p=platform/system/core.git;a=commit;h=b620a0b1c7ae486e979826200e8e441605b0a5d6', 'tags': ['Patch'], 'refsource': 'CONFIRM'}
  • {'url': 'http://android.git.kernel.org/?p=platform/system/netd.git;a=commit;h=79b579c92afc08ab12c0a5788d61f2dd2934836f', 'name': 'http://android.git.kernel.org/?p=platform/system/netd.git;a=commit;h=79b579c92afc08ab12c0a5788d61f2dd2934836f', 'tags': ['Patch'], 'refsource': 'CONFIRM'}
  • () http://android.git.kernel.org/?p=platform/system/core.git%3Ba=commit%3Bh=b620a0b1c7ae486e979826200e8e441605b0a5d6 -
  • () http://android.git.kernel.org/?p=platform/system/vold.git%3Ba=commit%3Bh=c51920c82463b240e2be0430849837d6fdc5352e -
  • () http://android.git.kernel.org/?p=platform/system/netd.git%3Ba=commit%3Bh=79b579c92afc08ab12c0a5788d61f2dd2934836f -

Information

Published : 2011-06-09 10:36

Updated : 2024-11-21 01:27


NVD link : CVE-2011-1823

Mitre link : CVE-2011-1823

CVE.ORG link : CVE-2011-1823


JSON object : View

Products Affected

google

  • android
CWE
CWE-190

Integer Overflow or Wraparound