Android 1.5 CRBxx allows local users to bypass the (1) Manifest.permission.CAMERA (aka android.permission.CAMERA) and (2) Manifest.permission.AUDIO_RECORD (aka android.permission.RECORD_AUDIO) configuration settings by installing and executing an application that does not make a permission request before using the camera or microphone.
References
Configurations
History
21 Nov 2024, 01:04
Type | Values Removed | Values Added |
---|---|---|
References | () http://android.git.kernel.org/?p=platform/frameworks/base.git%3Ba=commit%3Bh=4d8adefd35efdea849611b8b02d61f9517e47760 - | |
References | () http://android.git.kernel.org/?p=platform/frameworks/base.git%3Ba=commit%3Bh=7b7225c8fdbead25235c74811b30ff4ee690dc58 - | |
References | () http://android.git.kernel.org/?p=platform/packages/apps/Camera.git%3Ba=commit%3Bh=e655d54160e5a56d4909f2459eeae9012e9f187f - | |
References | () http://www.ocert.org/advisories/ocert-2009-011.html - | |
References | () http://www.openwall.com/lists/oss-security/2009/07/16/4 - | |
References | () http://www.securityfocus.com/archive/1/505012/100/0/threaded - | |
References | () http://www.securityfocus.com/bid/35717 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/51798 - |
Information
Published : 2009-07-17 16:30
Updated : 2024-11-21 01:04
NVD link : CVE-2009-2348
Mitre link : CVE-2009-2348
CVE.ORG link : CVE-2009-2348
JSON object : View
Products Affected
- android
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')