Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2011-1149

Description

Android before 2.3 does not properly restrict access to the system property space, which allows local applications to bypass the application sandbox and gain privileges, as demonstrated by psneuter and KillingInTheNameOf, related to the use of Android shared memory (ashmem) and ASHMEM_SET_PROT_MASK.

POC

Reference

- http://forum.xda-developers.com/wiki/index.php?title=HTC_Vision#Rooting_the_G2

Github

- https://github.com/c-skills/CVEs

- https://github.com/tangsilian/android-vuln