The backup mechanism in the adb tool in Android might allow attackers to inject additional applications (APKs) and execute arbitrary code by leveraging failure to filter application data streams.
References
Configurations
History
21 Nov 2024, 02:18
Type | Values Removed | Values Added |
---|---|---|
References | () http://packetstormsecurity.com/files/132645/ADB-Backup-APK-Injection.html - Exploit, Third Party Advisory, VDB Entry | |
References | () http://seclists.org/fulldisclosure/2015/Jul/46 - Exploit, Mailing List, Third Party Advisory | |
References | () http://www.search-lab.hu/about-us/news/110-android-adb-backup-apk-injection-vulnerability - Exploit, Third Party Advisory | |
References | () http://www.securityfocus.com/archive/1/535980/100/0/threaded - | |
References | () http://www.securityfocus.com/bid/75705 - Third Party Advisory, VDB Entry | |
References | () https://github.com/irsl/ADB-Backup-APK-Injection/ - Exploit, Third Party Advisory |
Information
Published : 2018-01-12 17:29
Updated : 2024-11-21 02:18
NVD link : CVE-2014-7952
Mitre link : CVE-2014-7952
CVE.ORG link : CVE-2014-7952
JSON object : View
Products Affected
- android
CWE
CWE-74
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')