CVE-2009-2348

Android 1.5 CRBxx allows local users to bypass the (1) Manifest.permission.CAMERA (aka android.permission.CAMERA) and (2) Manifest.permission.AUDIO_RECORD (aka android.permission.RECORD_AUDIO) configuration settings by installing and executing an application that does not make a permission request before using the camera or microphone.
Configurations

Configuration 1 (hide)

cpe:2.3:o:google:android:1.5:*:*:*:*:*:*:*

History

21 Nov 2024, 01:04

Type Values Removed Values Added
References () http://android.git.kernel.org/?p=platform/frameworks/base.git%3Ba=commit%3Bh=4d8adefd35efdea849611b8b02d61f9517e47760 - () http://android.git.kernel.org/?p=platform/frameworks/base.git%3Ba=commit%3Bh=4d8adefd35efdea849611b8b02d61f9517e47760 -
References () http://android.git.kernel.org/?p=platform/frameworks/base.git%3Ba=commit%3Bh=7b7225c8fdbead25235c74811b30ff4ee690dc58 - () http://android.git.kernel.org/?p=platform/frameworks/base.git%3Ba=commit%3Bh=7b7225c8fdbead25235c74811b30ff4ee690dc58 -
References () http://android.git.kernel.org/?p=platform/packages/apps/Camera.git%3Ba=commit%3Bh=e655d54160e5a56d4909f2459eeae9012e9f187f - () http://android.git.kernel.org/?p=platform/packages/apps/Camera.git%3Ba=commit%3Bh=e655d54160e5a56d4909f2459eeae9012e9f187f -
References () http://www.ocert.org/advisories/ocert-2009-011.html - () http://www.ocert.org/advisories/ocert-2009-011.html -
References () http://www.openwall.com/lists/oss-security/2009/07/16/4 - () http://www.openwall.com/lists/oss-security/2009/07/16/4 -
References () http://www.securityfocus.com/archive/1/505012/100/0/threaded - () http://www.securityfocus.com/archive/1/505012/100/0/threaded -
References () http://www.securityfocus.com/bid/35717 - () http://www.securityfocus.com/bid/35717 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/51798 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/51798 -

Information

Published : 2009-07-17 16:30

Updated : 2024-11-21 01:04


NVD link : CVE-2009-2348

Mitre link : CVE-2009-2348

CVE.ORG link : CVE-2009-2348


JSON object : View

Products Affected

google

  • android
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')