android.git.kernel.orgConfirmation
http://android.git.kernel.org/?p=platform/cts.git%3Ba=commit%3Bh=7e48fb87d48d27e65942b53b7918288c8d740e17 CVE-2011-2357
Open Handset Alliance Android 2.3.4/3.1 - Browser Sandbox Security Bypass
Record summary
CVE-2011-2357 has a selected CVSS score of 4.3; EIP currently links 1 catalogued exploit.
Description
Cross-application scripting vulnerability in the Browser URL loading functionality in Android 2.3.4 and 3.1 allows local applications to bypass the sandbox and execute arbitrary Javascript in arbitrary domains by (1) causing the MAX_TAB number of tabs to be opened, then loading a URI to the targeted domain into the current tab, or (2) making two startActivity function calls beginning with the targeted domain's URI followed by the malicious Javascript while the UI focus is still associated with the targeted domain.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBOpen Handset Alliance Android 2.3.4/3.1 - Browser Sandbox Security BypassExploitDB exploitby Roee HayNot analyzed1 file
References
Showing 12 of 19android.git.kernel.org
http://android.git.kernel.org/?p=platform/cts.git;a=commit;h=7e48fb87d48d27e65942b53b7918288c8d740e17 android.git.kernel.orgConfirmation
http://android.git.kernel.org/?p=platform/packages/apps/Browser.git%3B%20a=commit%3Bh=096bae248453abe83cbb2e5a2c744bd62cdb620b android.git.kernel.orgConfirmation
http://android.git.kernel.org/?p=platform/packages/apps/Browser.git%3B%20a=commit%3Bh=afa4ab1e4c1d645e34bd408ce04cadfd2e5dae1e android.git.kernel.org
http://android.git.kernel.org/?p=platform/packages/apps/Browser.git;%20a=commit;h=096bae248453abe83cbb2e5a2c744bd62cdb620b android.git.kernel.org
http://android.git.kernel.org/?p=platform/packages/apps/Browser.git;%20a=commit;h=afa4ab1e4c1d645e34bd408ce04cadfd2e5dae1e blog.watchfire.com
http://blog.watchfire.com/files/advisory-android-browser.pdf blog.watchfire.com
http://blog.watchfire.com/wfblog/2011/08/android-browser-cross-application-scripting-cve-2011-2357.html 74260vdb entry
http://osvdb.org/74260 20110802 Android Browser Cross-Application Scripting (CVE-2011-2357)mailing list
http://seclists.org/fulldisclosure/2011/Aug/9 45457Third-party advisory
http://secunia.com/advisories/45457 8335Third-party advisory
http://securityreason.com/securityalert/8335