CVE

Id
66071  
CVE No.
CVE-2013-6124  
Status
Candidate  
Description
The Qualcomm Innovation Center (QuIC) init scripts in Code Aurora Forum (CAF) releases of Android 4.1.x through 4.4.x allow local users to modify file metadata via a symlink attack on a file accessed by a (1) chown or (2) chmod command, as demonstrated by changing the permissions of an arbitrary file via an attack on the sensor-settings file.  
Phase
Assigned (20131015)  
Votes
None (candidate not yet proposed)  
Comments