Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r6m5-h8c2-mqqc

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.4

Описание

Race condition in Download Manager in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 allows attackers to bypass private-storage file-access restrictions via a crafted application that changes a symlink target, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 26211054.

Race condition in Download Manager in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 allows attackers to bypass private-storage file-access restrictions via a crafted application that changes a symlink target, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 26211054.

EPSS

Процентиль: 1%
0.00012
Низкий

8.4 High

CVSS3

Дефекты

CWE-362

Связанные уязвимости

CVSS3: 8.4
ubuntu
почти 10 лет назад

Race condition in Download Manager in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 allows attackers to bypass private-storage file-access restrictions via a crafted application that changes a symlink target, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 26211054.

CVSS3: 8.4
nvd
почти 10 лет назад

Race condition in Download Manager in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 allows attackers to bypass private-storage file-access restrictions via a crafted application that changes a symlink target, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 26211054.

fstec
почти 10 лет назад

Уязвимость операционной системы Android, позволяющая нарушителю обойти существующие ограничения доступа к частным файлам

EPSS

Процентиль: 1%
0.00012
Низкий

8.4 High

CVSS3

Дефекты

CWE-362