CVE-2009-2348

Android 1.5 CRBxx allows local users to bypass the (1) Manifest.permission.CAMERA (aka android.permission.CAMERA) and (2) Manifest.permission.AUDIO_RECORD (aka android.permission.RECORD_AUDIO) configuration settings by installing and executing an application that does not make a permission request before using the camera or microphone.
Configurations

Configuration 1 (hide)

cpe:2.3:o:google:android:1.5:*:*:*:*:*:*:*

History

07 Nov 2023, 02:04

Type Values Removed Values Added
References
  • {'url': 'http://android.git.kernel.org/?p=platform/frameworks/base.git;a=commit;h=7b7225c8fdbead25235c74811b30ff4ee690dc58', 'name': 'http://android.git.kernel.org/?p=platform/frameworks/base.git;a=commit;h=7b7225c8fdbead25235c74811b30ff4ee690dc58', 'tags': ['Vendor Advisory'], 'refsource': 'CONFIRM'}
  • {'url': 'http://android.git.kernel.org/?p=platform/frameworks/base.git;a=commit;h=4d8adefd35efdea849611b8b02d61f9517e47760', 'name': 'http://android.git.kernel.org/?p=platform/frameworks/base.git;a=commit;h=4d8adefd35efdea849611b8b02d61f9517e47760', 'tags': ['Vendor Advisory'], 'refsource': 'CONFIRM'}
  • {'url': 'http://android.git.kernel.org/?p=platform/packages/apps/Camera.git;a=commit;h=e655d54160e5a56d4909f2459eeae9012e9f187f', 'name': 'http://android.git.kernel.org/?p=platform/packages/apps/Camera.git;a=commit;h=e655d54160e5a56d4909f2459eeae9012e9f187f', 'tags': ['Vendor Advisory'], 'refsource': 'CONFIRM'}
  • () http://android.git.kernel.org/?p=platform/packages/apps/Camera.git%3Ba=commit%3Bh=e655d54160e5a56d4909f2459eeae9012e9f187f -
  • () http://android.git.kernel.org/?p=platform/frameworks/base.git%3Ba=commit%3Bh=7b7225c8fdbead25235c74811b30ff4ee690dc58 -
  • () http://android.git.kernel.org/?p=platform/frameworks/base.git%3Ba=commit%3Bh=4d8adefd35efdea849611b8b02d61f9517e47760 -

Information

Published : 2009-07-17 16:30

Updated : 2023-12-10 10:51


NVD link : CVE-2009-2348

Mitre link : CVE-2009-2348

CVE.ORG link : CVE-2009-2348


JSON object : View

Products Affected

google

  • android
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')