CVE-2012-5564Link Following in Android-platform-system-core

CWE-59Link Following7 documents6 sources
Severity
3.3LOWNVD
EPSS
0.0%
top 93.33%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 14
Latest updateMay 17

Description

android-tools 4.1.1 in Android Debug Bridge (ADB) allows local users to overwrite arbitrary files via a symlink attack on /tmp/adb.log.

CVSS vector

AV:L/AC:M/C:N/I:P/A:PExploitability: 3.4 | Impact: 4.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-h3mc-wgf6-6vpg: android-tools 42022-05-17
OSV
CVE-2012-5564: android-tools 42013-02-14

📋Vendor Advisories

1
Debian
CVE-2012-5564: android-platform-system-core - android-tools 4.1.1 in Android Debug Bridge (ADB) allows local users to overwrit...2012

📄Research Papers

1
arXiv
The Security War in File Systems: An Empirical Study from A Vulnerability-Centric Perspective2022-04-26

💬Community

2
Bugzilla
CVE-2012-5564 android-tools (server): Insecure temporary file used for logging [fedora-all]2012-11-23
Bugzilla
CVE-2012-5564 android-tools (server): Insecure temporary file used for logging2012-11-23