Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2014-7952

Description

The backup mechanism in the adb tool in Android might allow attackers to inject additional applications (APKs) and execute arbitrary code by leveraging failure to filter application data streams.

POC

Reference

- http://packetstormsecurity.com/files/132645/ADB-Backup-APK-Injection.html

- http://seclists.org/fulldisclosure/2015/Jul/46

- http://www.search-lab.hu/about-us/news/110-android-adb-backup-apk-injection-vulnerability

- https://github.com/irsl/ADB-Backup-APK-Injection/

Github

- https://github.com/irsl/ADB-Backup-APK-Injection