CVE-2013-6768: Path Traversal
Untrusted search path vulnerability in the CyanogenMod/ClockWorkMod/Koush Superuser package 1.0.2.1 for Android 4.2.x and earlier allows attackers to trigger the launch of a Trojan horse appprocess program via a crafted PATH environment variable for a /system/xbin/su process.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-6768?
CVE-2013-6768 is considered to have a high severity due to the potential for remote exploitation.
How do I fix CVE-2013-6768?
To fix CVE-2013-6768, you should upgrade to a version of the Koushik Dutta Superuser package that is not vulnerable.
Which versions are affected by CVE-2013-6768?
CVE-2013-6768 specifically affects the Koushik Dutta Superuser package version 1.0.2.1.
What happens if CVE-2013-6768 is exploited?
If CVE-2013-6768 is exploited, attackers can launch a Trojan horse app through a manipulated PATH environment variable.
Is there a workaround for CVE-2013-6768?
Currently, the best workaround for CVE-2013-6768 is to ensure that the vulnerable version of the Koushik Dutta Superuser package is not installed.