← Back

CVE-2013-6774

nvd nist
Published: Mar 31, 2014Modified: May 6, 2026

JSON object

Loading...
10.0
Vector
AV:N/AC:L/Au:N/C:C/I:C/A:C
Exploitability: 10.0 / Impact: 10.0
Source: NVD

Description

Untrusted search path vulnerability in the ChainsDD Superuser package 3.1.3 for Android 4.2.x and earlier, CyanogenMod/ClockWorkMod/Koush Superuser package 1.0.2.1 for Android 4.2.x and earlier, and Chainfire SuperSU package before 1.69 for Android 4.2.x and earlier allows attackers to load an arbitrary .jar file and gain privileges via a crafted BOOTCLASSPATH environment variable for a /system/xbin/su process. NOTE: another researcher was unable to reproduce this with ChainsDD Superuser.

Affected (3)

1 product
Supersu
1 product
Chainsdd Superuser
1 product
Superuser
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 1.69
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 3.1.3
Configuration C
1 vulnerable · 38 platform
Vulnerable SoftwareAffected Versions
Version 1.0.2.1
Running on/withPlatform Versions
Google
Android
Version 1.0
Google
Android
Version 1.1
Google
Android
Version 1.5
Google
Android
Version 1.6
Google
Android
Version 2.0.1
Google
Android
Version 2.0
Google
Android
Version 2.1
Google
Android
Version 2.2.1
Google
Android
Version 2.2.2
Google
Android
Version 2.2.3
Google
Android
Version 2.2
Google
Android
Version 2.2 rev1
Google
Android
Version 2.3.1
Google
Android
Version 2.3.2
Google
Android
Version 2.3.3
Google
Android
Version 2.3.4
Google
Android
Version 2.3.5
Google
Android
Version 2.3.6
Google
Android
Version 2.3.7
Google
Android
Version 2.3
Google
Android
Version 2.3 rev1
Google
Android
Version 3.0
Google
Android
Version 3.1
Google
Android
Version 3.2.1
Google
Android
Version 3.2.2
Google
Android
Version 3.2.4
Google
Android
Version 3.2.6
Google
Android
Version 3.2
Google
Android
Version 4.0.1
Google
Android
Version 4.0.2
Google
Android
Version 4.0.3
Google
Android
Version 4.0.4
Google
Android
Version 4.0
Google
Android
Version 4.1.2
Google
Android
Version 4.1
Google
Android
Version 4.2.1
Google
Android
Version 4.2.2
Google
Android
Version 4.2

References (4)

Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.