Release date:
Updated on: 2013-06-25
Affected Systems:
Spritesoftware Backup
Spritesoftware spritebud
LG Optimus G
Description:
--------------------------------------------------------------------------------
Bugtraq id: 60749
CVE (CAN) ID: CVE-2013-3685
"Backup" and "spritebud" are application Backup/recovery systems compiled by Sprite Software and used on LG Android smartphones.
Spritebud 1.3.24 and backup 2.5.4105 have the Local Privilege Escalation Vulnerability. Local attackers can exploit this vulnerability to obtain the root privilege of the affected device. The "spritebud" background program is started by the init script and runs as the root user. It listens to the unix socket and accepts the commands of the "Backup" application. Through Special backup, attackers can write any file, change its permissions and ownership.
<* Source: Justin Case
Link: http://seclists.org/fulldisclosure/2013/Jun/196
Https://plus.google.com/110348415484169880343/posts/Me2yea2PgwE
Https://github.com/CunningLogic/LGPwn
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Spritesoftware
--------------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.spritesoftware.com/