Vulnerability CVE-2009-2348


Published: 2009-07-17   Modified: 2012-02-13

Description:
Android 1.5 CRBxx allows local users to bypass the (1) Manifest.permission.CAMERA (aka android.permission.CAMERA) and (2) Manifest.permission.AUDIO_RECORD (aka android.permission.RECORD_AUDIO) configuration settings by installing and executing an application that does not make a permission request before using the camera or microphone.

See advisories in our WLB2 database:
Topic
Author
Date
Med.
Android improper camera and audio permissionverification
Andrea Barisani
21.07.2009

Type:

CWE-94

(Improper Control of Generation of Code ('Code Injection'))

CVSS2 => (AV:L/AC:M/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
6.9/10
10/10
3.4/10
Exploit range
Attack complexity
Authentication
Local
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete
Affected software
Google -> Android 
Android -> Android 

 References:
http://android.git.kernel.org/?p=platform/frameworks/base.git;a=commit;h=4d8adefd35efdea849611b8b02d61f9517e47760
http://android.git.kernel.org/?p=platform/frameworks/base.git;a=commit;h=7b7225c8fdbead25235c74811b30ff4ee690dc58
http://android.git.kernel.org/?p=platform/packages/apps/Camera.git;a=commit;h=e655d54160e5a56d4909f2459eeae9012e9f187f
http://www.ocert.org/advisories/ocert-2009-011.html
http://www.openwall.com/lists/oss-security/2009/07/16/4
http://www.securityfocus.com/archive/1/505012/100/0/threaded
http://www.securityfocus.com/bid/35717
https://exchange.xforce.ibmcloud.com/vulnerabilities/51798

Copyright 2024, cxsecurity.com

 

Back to Top