bluebox.com
http://bluebox.com/corporate-blog/bluebox-uncovers-android-master-key CVE-2013-4787
Google Android - 'APK' code Remote Security Bypass
Record summary
CVE-2013-4787 has a selected CVSS score of 9.3; EIP currently links 1 catalogued exploit.
Description
Android 1.6 Donut through 4.2 Jelly Bean does not properly check cryptographic signatures for applications, which allows attackers to execute arbitrary code via an application package file (APK) that is modified in a way that does not violate the cryptographic signature, probably involving multiple entries in a Zip file with the same name in which one entry is validated but the other entry is installed, aka Android security bug 8219321 and the "Master Key" vulnerability.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBGoogle Android - 'APK' code Remote Security BypassExploitDB exploitby Bluebox SecurityNot analyzed1 file
References
8review.cyanogenmod.org
http://review.cyanogenmod.org/ 94773vdb entry
http://www.osvdb.org/94773 60952vdb entry
http://www.securityfocus.com/bid/60952 zdnet.com
http://www.zdnet.com/google-releases-fix-to-oems-for-blue-security-android-security-hole-7000017782 jira.cyanogenmod.org
https://jira.cyanogenmod.org/browse/CYAN-1602 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2013-4787 plus.google.com
https://plus.google.com/113331808607528811927/posts/GxDA6111vYy