Actions
Issue #1113
closedPrivilege Escalation vulnerability - CVE-2014-7911
Start date:
12/08/2014
Due date:
% Done:
0%
Estimated time:
Resolution:
fixed
Device:
Grant:
Type of work:
Description
Description
I've checked, that Replicant is vulnerable to the Privilege Escalation (using ObjectInputStream), registered as CVE-2014-7911
more informations: http://seclists.org/fulldisclosure/2014/Nov/51
Solution
AOSP (5.0) patch: https://android.googlesource.com/platform/libcore/+/738c833d38d41f8f76eb7e77ab39add82b1ae1e2
CM commit: https://github.com/CyanogenMod/android_libcore/commit/2d0fbea07c1a3c4368ddb07609d1a86993ed6de9
Actions