MEDIUM
LineageOS 16.0 and earlier is affected by: Incorrect Access Control
Published Jul 23, 2019
6.8
MEDIUMCVSS 3.0
EPSS 0.37%
Description
LineageOS 16.0 and earlier is affected by: Incorrect Access Control. The impact is: The property checked by `adb root` can also be set in a normal adb shell session. The component is: adb shell (patches to fix this are at https://review.lineageos.org/c/LineageOS/android_system_core/+/234800, https://review.lineageos.org/c/LineageOS/android_device_lineage_sepolicy/+/234799). The attack vector is: When adb is enabled, and an attacker has physical access, `adb shell setprop service.adb.root 1` allows restarting adb as root.
Affected products
-
- Version 16.0 and earlierStatusaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (0)
No CWE recorded.
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-1963 Advisory
- https://gist.github.com/zifnab06/e31ad63596b63a95e061bfe1f49ff0a7 x_refsource_MISCPatchThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-1963 | Advisory | |
| https://gist.github.com/zifnab06/e31ad63596b63a95e061bfe1f49ff0a7 | x_refsource_MISCPatchThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner dwf
Published Jul 23, 2019
Updated Aug 5, 2024
Reserved Mar 20, 2019
Link CVE-2019-1010221
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2019-1963 Assigner dwf
Published Jul 23, 2019
Updated Aug 5, 2024
Exploited since n/a
Link EUVD-2019-1963