CVE-2011-1149

EUVD-2011-1163
Android before 2.3 does not properly restrict access to the system property space, which allows local applications to bypass the application sandbox and gain privileges, as demonstrated by psneuter and KillingInTheNameOf, related to the use of Android shared memory (ashmem) and ASHMEM_SET_PROT_MASK.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.2 UNKNOWN
LOCAL
LOW
AV:L/AC:L/Au:N/C:C/I:C/A:C
Base Score
CVSS 3.x
EPSS Score
Percentile: 10%
Affected Products (NVD)
VendorProductVersion
googleandroid
𝑥
≤ 2.2.2
googleandroid
1.5
googleandroid
1.6
googleandroid
2.1
googleandroid
2.2:rev1
googleandroid
2.2.1
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
linux-flo
lucid
dne
precise
dne
quantal
dne
saucy
dne
trusty
ignored
utopic
ignored
vivid
ignored
wily
ignored
xenial
ignored
yakkety
ignored
zesty
dne
linux-goldfish
lucid
dne
precise
dne
quantal
dne
saucy
ignored
trusty
ignored
utopic
ignored
vivid
ignored
wily
ignored
xenial
ignored
yakkety
ignored
zesty
ignored
linux-grouper
lucid
dne
precise
dne
quantal
dne
saucy
ignored
trusty
ignored
utopic
ignored
vivid
dne
wily
dne
xenial
dne
yakkety
dne
zesty
dne
linux-maguro
lucid
dne
precise
dne
quantal
dne
saucy
ignored
trusty
dne
utopic
dne
vivid
dne
wily
dne
xenial
dne
yakkety
dne
zesty
dne
linux-mako
lucid
dne
precise
dne
quantal
dne
saucy
ignored
trusty
ignored
utopic
ignored
vivid
ignored
wily
ignored
xenial
ignored
yakkety
ignored
zesty
dne
linux-manta
lucid
dne
precise
dne
quantal
dne
saucy
ignored
trusty
ignored
utopic
ignored
vivid
ignored
wily
ignored
xenial
dne
yakkety
dne
zesty
dne
Common Weakness Enumeration