SB2018011219 - Improper Neutralization of Special Elements in Output Used by a Downstream Component in Google, Google Android
Published: January 12, 2018 Updated: August 8, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper Neutralization of Special Elements in Output Used by a Downstream Component (CVE-ID: CVE-2014-7952)
The vulnerability allows a local authenticated user to execute arbitrary code.
The backup mechanism in the adb tool in Android might allow attackers to inject additional applications (APKs) and execute arbitrary code by leveraging failure to filter application data streams.
Remediation
Install update from vendor's website.
References
- http://packetstormsecurity.com/files/132645/ADB-Backup-APK-Injection.html
- http://seclists.org/fulldisclosure/2015/Jul/46
- http://www.search-lab.hu/about-us/news/110-android-adb-backup-apk-injection-vulnerability
- http://www.securityfocus.com/archive/1/535980/100/0/threaded
- http://www.securityfocus.com/bid/75705
- https://github.com/irsl/ADB-Backup-APK-Injection/