The Chainfire SuperSU package before 1.69 for Android allows attackers to gain privileges via the (1) backtick or (2) $() type of shell metacharacters in the -c option to /system/xbin/su.
                
            References
                    | Link | Resource | 
|---|---|
| http://www.securityfocus.com/archive/1/529797 | Exploit | 
| http://www.securityfocus.com/archive/1/529797 | Exploit | 
Configurations
                    Configuration 1 (hide)
| AND | 
 
 | 
History
                    No history.
Information
                Published : 2014-03-31 14:58
Updated : 2025-04-12 10:46
NVD link : CVE-2013-6775
Mitre link : CVE-2013-6775
CVE.ORG link : CVE-2013-6775
JSON object : View
Products Affected
                - android
chainfire
- supersu
CWE
                
                    
                        
                        CWE-264
                        
            Permissions, Privileges, and Access Controls
