The backup mechanism in the adb tool in Android might allow attackers to inject additional applications (APKs) and execute arbitrary code by leveraging failure to filter application data streams.
References
| Link | Resource |
|---|---|
| http://packetstormsecurity.com/files/132645/ADB-Backup-APK-Injection.html | Exploit Third Party Advisory VDB Entry |
| http://seclists.org/fulldisclosure/2015/Jul/46 | Exploit Mailing List Third Party Advisory |
| http://www.search-lab.hu/about-us/news/110-android-adb-backup-apk-injection-vulnerability | Exploit Third Party Advisory |
| http://www.securityfocus.com/archive/1/535980/100/0/threaded | |
| http://www.securityfocus.com/bid/75705 | Third Party Advisory VDB Entry |
| https://github.com/irsl/ADB-Backup-APK-Injection/ | Exploit Third Party Advisory |
Configurations
History
No history.
Information
Published : 2018-01-12 17:29
Updated : 2018-10-09 19:53
NVD link : CVE-2014-7952
Mitre link : CVE-2014-7952
CVE.ORG link : CVE-2014-7952
JSON object : View
Products Affected
- android
CWE
CWE-74
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
