CVE-2011-1149
Severity CVSS v4.0:
Pending analysis
Type:
CWE-264
Permissions, Privileges, and Access Control
Publication date:
21/04/2011
Last modified:
11/04/2025
Description
Android before 2.3 does not properly restrict access to the system property space, which allows local applications to bypass the application sandbox and gain privileges, as demonstrated by psneuter and KillingInTheNameOf, related to the use of Android shared memory (ashmem) and ASHMEM_SET_PROT_MASK.
Impact
Base Score 2.0
7.20
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:google:android:*:*:*:*:*:*:*:* | 2.2.2 (including) | |
| cpe:2.3:o:google:android:1.5:*:*:*:*:*:*:* | ||
| cpe:2.3:o:google:android:1.6:*:*:*:*:*:*:* | ||
| cpe:2.3:o:google:android:2.1:*:*:*:*:*:*:* | ||
| cpe:2.3:o:google:android:2.2:rev1:*:*:*:*:*:* | ||
| cpe:2.3:o:google:android:2.2.1:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://android.git.kernel.org/?p=kernel/common.git%3Ba%3Dcommit%3Bh%3Dc98a285075f26e2b17a5baa2cb3eb6356a75597e
- http://android.git.kernel.org/?p=platform/system/core.git%3Ba%3Dcommit%3Bh%3D25b15be9120bcdaa0aba622c67ad2c835d9e91ca
- http://c-skills.blogspot.com/2011/01/adb-trickery-again.html
- http://forum.xda-developers.com/wiki/index.php?title=HTC_Vision#Rooting_the_G2
- http://groups.google.com/group/android-security-discuss/browse_thread/thread/15f97658c88d6827/e86db04652651971?show_docid=e86db04652651971
- https://github.com/tmzt/g2root-kmod/tree/scotty2/scotty2
- http://android.git.kernel.org/?p=kernel/common.git%3Ba%3Dcommit%3Bh%3Dc98a285075f26e2b17a5baa2cb3eb6356a75597e
- http://android.git.kernel.org/?p=platform/system/core.git%3Ba%3Dcommit%3Bh%3D25b15be9120bcdaa0aba622c67ad2c835d9e91ca
- http://c-skills.blogspot.com/2011/01/adb-trickery-again.html
- http://forum.xda-developers.com/wiki/index.php?title=HTC_Vision#Rooting_the_G2
- http://groups.google.com/group/android-security-discuss/browse_thread/thread/15f97658c88d6827/e86db04652651971?show_docid=e86db04652651971
- https://github.com/tmzt/g2root-kmod/tree/scotty2/scotty2



