CVE
- Id
- 66071
- CVE No.
- CVE-2013-6124
- Status
- Candidate
- Description
- The Qualcomm Innovation Center (QuIC) init scripts in Code Aurora Forum (CAF) releases of Android 4.1.x through 4.4.x allow local users to modify file metadata via a symlink attack on a file accessed by a (1) chown or (2) chmod command, as demonstrated by changing the permissions of an arbitrary file via an attack on the sensor-settings file.
- Phase
- Assigned (20131015)
- Votes
- None (candidate not yet proposed)
- Comments