First published: Wed Sep 25 2013(Updated: )
Stack-based buffer overflow in the sub_E110 function in init in a certain configuration of Android 2.3.7 on the Motorola Defy XT phone for Republic Wireless allows local users to gain privileges or cause a denial of service (memory corruption) by writing a long string to the /dev/socket/init_runit socket that is inconsistent with a certain length value that was previously written to this socket.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Android | =2.3.7 | |
Motorola Defy XT |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2013-5933 is considered high due to the potential for local users to gain elevated privileges or cause a denial of service.
To fix CVE-2013-5933, the affected device should be updated to a version of Android that is not vulnerable.
CVE-2013-5933 specifically affects users of Motorola Defy XT devices running Android 2.3.7.
CVE-2013-5933 is a stack-based buffer overflow vulnerability that can be exploited by writing excessively long strings.
CVE-2013-5933 requires local access to the device, so it cannot be exploited remotely.