CVE-2020-13833
published 2020-06-04CVE-2020-13833: An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. The system area allows arbitrary file overwrites via a symlink…
PriorityP340critical9.1CVSS 3.1
AVNACLPRNUINSUCNIHAH
EPSS
0.46%
37.6th percentile
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. The system area allows arbitrary file overwrites via a symlink attack. The Samsung ID is SVE-2020-17183 (June 2020).
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
arXiv
Static Detection of Filesystem Vulnerabilities in Android Systems
arxiv_fulltext·2024-07-15
Static Detection of Filesystem Vulnerabilities in Android Systems
Static Detection of Filesystem Vulnerabilities
in Android Systems
Yu-Tsung Lee
Penn State University
[email protected]
Hayawardh Vijayakumar
Samsung Resaerch America
[email protected]
Zhiyun Qian
UC Riverside
[email protected]
Trent Jaeger^ More authors to be added pending corporate approval.
UC Riverside
[email protected]
## Abstract
Filesystem vulnerabilities persist as a significant threat to Android systems, despite various proposed defenses and testing techniques. The complexity of program behaviors and access control mechanisms in Android systems makes it challenging to effectively identify these vulnerabilities. In this paper, we present , which overcomes the limitations of previous techniques by combining static program analysis and access control policy analysis to d
arXiv
PolyScope: Multi-Policy Access Control Analysis to Triage Android Systems
arxiv_fulltext·2020-08-08
PolyScope: Multi-Policy Access Control Analysis to Triage Android Systems
PolyScope: Multi-Policy Access Control Analysis to Triage Android Systems
Yu-Tsung Lee
Penn State University
William Enck
North Carolina State University
Haining Chen
Google
Hayawardh Vijayakumar
Samsung Research
Ninghui Li
Purdue University
Daimeng Wang, Zhiyun Qian
University of California, Riverside
Giuseppe Petracca Giuseppe Petracca's work on this paper was performed when he was a graduate student at Penn State.
Lyft
Trent Jaeger
Penn State University
## Abstract
Android's filesystem access control provides a foundation for Android system integrity.
Android utilizes a combination of mandatory (e.g., SEAndroid) and discretionary (e.g., UNIX permissions) access control, both to protect the Android platform from Android/OEM services and to protect Android/OEM services f
2020-06-04
Published