Vulnerability Description
A Privilege Escalation Vulnerability exists in Sprite Software Spritebud 1.3.24 and 1.3.28 and Backup 2.5.4105 and 2.5.4108 on LG Android smartphones due to a race condition in the spritebud daemon, which could let a local malicious user obtain root privileges.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Spritesoftware | Spritebackup | 2.5.4105 |
| Spritesoftware | Spritebud | 1.3.24 |
| Lg | E971 | - |
| Lg | E973 | - |
| Lg | E975 | - |
| Lg | E975K | - |
| Lg | E975T | - |
| Lg | E976 | - |
| Lg | E977 | - |
| Lg | F100K | - |
| Lg | F100L | - |
| Lg | F100S | - |
| Lg | F120K | - |
| Lg | F120L | - |
| Lg | F120S | - |
| Lg | F160K | - |
| Lg | F160L | - |
| Lg | F160Lv | - |
| Lg | F160S | - |
| Lg | F180K | - |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/60749Third Party AdvisoryVDB Entry
- https://androidvulnerabilities.org/allThird Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/85296Third Party AdvisoryVDB Entry
- https://seclists.org/fulldisclosure/2013/Jun/196ExploitMailing ListThird Party Advisory
- http://www.securityfocus.com/bid/60749Third Party AdvisoryVDB Entry
- https://androidvulnerabilities.org/allThird Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/85296Third Party AdvisoryVDB Entry
- https://seclists.org/fulldisclosure/2013/Jun/196ExploitMailing ListThird Party Advisory
FAQ
What is CVE-2013-3685?
CVE-2013-3685 is a vulnerability with a CVSS score of 7.0 (HIGH). A Privilege Escalation Vulnerability exists in Sprite Software Spritebud 1.3.24 and 1.3.28 and Backup 2.5.4105 and 2.5.4108 on LG Android smartphones due to a race condition in the spritebud daemon, w...
How severe is CVE-2013-3685?
CVE-2013-3685 has been rated HIGH with a CVSS base score of 7.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2013-3685?
Check the references section above for vendor advisories and patch information. Affected products include: Spritesoftware Spritebackup, Spritesoftware Spritebud, Lg E971, Lg E973, Lg E975.