Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The CyanogenMod/ClockWorkMod/Koush Superuser package 1.0.2.1 for Android 4.3 and 4.4 does not properly restrict the set of users who can execute /system/xbin/su with the --daemon option, which allows attackers to gain privileges by leveraging ADB shell access and a certain Linux UID, and then creating a Trojan horse script.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
ClockWorkMod Superuser工具包权限许可和访问控制漏洞
Vulnerability Description
CyanogenMod/ClockWorkMod/Koush Superuser是一套用于Android平台中的超级用户授权工具。该工具通过授予应用程序root权限,可掌握手机的控制权。 Android 4.3和4.4版本的CyanogenMod/ClockWorkMod/Koush Superuser程序包1.0.2.1版本中存在安全漏洞,该漏洞源于程序没有正确设置执行带有--daemon选项的/system/xbin/su进程的用户权限。远程攻击者可借助ADB shell访问权限和Linux UID,
CVSS Information
N/A
Vulnerability Type
N/A