>From this list; << ccAndroid Security Discussions <[email protected]> dateFri, May 6, 2011 at 5:11 PMsubjectRe: [android-security-discuss] Security Fixes in Gingerbread MR2mailing list< android-security-discuss.googlegroups.com> Filter messages from this mailing listmailed-bygooglegroups.comsigned-bygooglegroups.comunsubscribeUnsubscribe from this mailing-listImportant mainly because of the words in the message. hide details May 6 It's CVE-2011-1823
The Android "vold" daemon improperly trusts messages received via a PF_NETLINK socket, resulting in a buffer underflow and elevated privileges, as demonstrated by the "GingerBreak" exploit. Patches: * http://android.git.kernel.org/?p=platform/system/core.git;a=commit;h=b620a0b1c7ae486e979826200e8e441605b0a5d6 * http://android.git.kernel.org/?p=platform/system/vold.git;a=commit;h=c51920c82463b240e2be0430849837d6fdc5352e * http://android.git.kernel.org/?p=platform/system/netd.git;a=commit;h=79b579c92afc08ab12c0a5788d61f2dd2934836f Misc: * http://c-skills.blogspot.com/2011/04/yummy-yummy-gingerbreak.html * http://forum.xda-developers.com/showthread.php?t=1044765 * http://stealth.openwall.net/xSports/GingerBreak.tgz -- Nick >> -Tim Strazzere On Mon, Aug 22, 2011 at 1:29 PM, mike <[email protected]> wrote: > I think the patch for this is > > http://android.git.kernel.org/?p=platform/system/core.git;a=commit;h=3a71970808df0331af29418f5e85435a5a6290a5 > > > -- > You received this message because you are subscribed to the Google Groups > "Android Security Discussions" group. > To view this discussion on the web visit > https://groups.google.com/d/msg/android-security-discuss/-/iyUsKAVIgGIJ. > > To post to this group, send email to > [email protected]. > To unsubscribe from this group, send email to > [email protected]. > For more options, visit this group at > http://groups.google.com/group/android-security-discuss?hl=en. > -- You received this message because you are subscribed to the Google Groups "Android Security Discussions" group. To post to this group, send email to [email protected]. To unsubscribe from this group, send email to [email protected]. For more options, visit this group at http://groups.google.com/group/android-security-discuss?hl=en.
