packetstormsecurity.com
http://packetstormsecurity.com/files/131510/ADB-Backup-Traversal-File-Overwrite.html CVE-2014-7951
MEDIUM
ADB - Backup Archive File Overwrite Directory Traversal
Record summary
CVE-2014-7951 has a selected CVSS score of 4.6 (medium); EIP currently links 1 catalogued exploit.
Description
Directory traversal vulnerability in the Android debug bridge (aka adb) in Android 4.0.4 allows physically proximate attackers with a direct connection to the target Android device to write to arbitrary files owned by system via a .. (dot dot) in the tar archive headers.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBADB - Backup Archive File Overwrite Directory TraversalExploitDB exploitby Imre RadNot analyzed1 file
References
7seclists.org
http://seclists.org/fulldisclosure/2015/Apr/51 securityfocus.com
http://www.securityfocus.com/bid/74211 android.googlesource.com
https://android.googlesource.com/platform/frameworks/base/+/7bc601d%5E! android.googlesource.com
https://android.googlesource.com/platform/frameworks/base/+/7bc601d%5E%21 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2014-7951 exploit-db.com
https://www.exploit-db.com/exploits/36813