CVE-2013-3685

Severity CVSS v4.0:
Pending analysis
Type:
CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
Publication date:
12/02/2020
Last modified:
19/02/2020

Description

A Privilege Escalation Vulnerability exists in Sprite Software Spritebud 1.3.24 and 1.3.28 and Backup 2.5.4105 and 2.5.4108 on LG Android smartphones due to a race condition in the spritebud daemon, which could let a local malicious user obtain root privileges.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:spritesoftware:spritebackup:2.5.4105:*:*:*:*:*:*:*
cpe:2.3:a:spritesoftware:spritebackup:2.5.4108:*:*:*:*:*:*:*
cpe:2.3:a:spritesoftware:spritebud:1.3.24:*:*:*:*:*:*:*
cpe:2.3:a:spritesoftware:spritebud:1.3.28:*:*:*:*:*:*:*
cpe:2.3:h:lg:e971:-:*:*:*:*:*:*:*
cpe:2.3:h:lg:e973:-:*:*:*:*:*:*:*
cpe:2.3:h:lg:e975:-:*:*:*:*:*:*:*
cpe:2.3:h:lg:e975k:-:*:*:*:*:*:*:*
cpe:2.3:h:lg:e975t:-:*:*:*:*:*:*:*
cpe:2.3:h:lg:e976:-:*:*:*:*:*:*:*
cpe:2.3:h:lg:e977:-:*:*:*:*:*:*:*
cpe:2.3:h:lg:f100k:-:*:*:*:*:*:*:*
cpe:2.3:h:lg:f100l:-:*:*:*:*:*:*:*
cpe:2.3:h:lg:f100s:-:*:*:*:*:*:*:*
cpe:2.3:h:lg:f120k:-:*:*:*:*:*:*:*