The Chainfire SuperSU package before 1.69 for Android allows attackers to gain privileges via the (1) backtick or (2) $() type of shell metacharacters in the -c option to /system/xbin/su.
                
            References
                    | Link | Resource | 
|---|---|
| http://www.securityfocus.com/archive/1/529797 | Exploit | 
Configurations
                    Configuration 1 (hide)
| AND | 
                                
                                
 
  | 
                        
Information
                Published : 2014-03-31 07:58
Updated : 2014-03-31 12:08
NVD link : CVE-2013-6775
Mitre link : CVE-2013-6775
JSON object : View
CWE
                
                    
                        
                        CWE-264
                        
            Permissions, Privileges, and Access Controls
Products Affected
                - android
 
chainfire
- supersu
 


