CVE-2013-4777: Medium severity Google Android vulnerability
A certain configuration of Android 2.3.7 on the Motorola Defy XT phone for Republic Wireless uses init to create a /dev/socket/initrunit socket that listens for shell commands, which allows local users to gain privileges by interacting with a LocalSocket object.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4777?
CVE-2013-4777 has a medium severity rating due to its potential to allow local privilege escalation.
How can I fix CVE-2013-4777?
To mitigate CVE-2013-4777, it is recommended to update the device to a version of Android that does not include this vulnerability.
What devices are affected by CVE-2013-4777?
CVE-2013-4777 specifically affects Motorola Defy XT phones running Android version 2.3.7.
How does CVE-2013-4777 exploit the system?
CVE-2013-4777 exploits the system by allowing local users to gain elevated privileges through the /dev/socket/init_runit socket.
Can CVE-2013-4777 be exploited remotely?
CVE-2013-4777 cannot be exploited remotely as it requires local access to the affected device.