A Privilege Escalation Vulnerability exists in Sprite Software Spritebud 1.3.24 and 1.3.28 and Backup 2.5.4105 and 2.5.4108 on LG Android smartphones due to a race condition in the spritebud daemon, which could let a local malicious user obtain root privileges.
The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/60749 | third party advisory vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/85296 | third party advisory vdb entry |
https://seclists.org/fulldisclosure/2013/Jun/196 | mailing list third party advisory exploit |
https://androidvulnerabilities.org/all | third party advisory |