mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-31 01:49:30 +02:00
39 lines
2.2 KiB
Markdown
39 lines
2.2 KiB
Markdown
### [CVE-2020-8913](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8913)
|
|

|
|

|
|

|
|
|
|
### Description
|
|
|
|
A local, arbitrary code execution vulnerability exists in the SplitCompat.install endpoint in Android's Play Core Library versions prior to 1.7.2. A malicious attacker could create an apk which targets a specific application, and if a victim were to install this apk, the attacker could perform a directory traversal, execute code as the targeted application and access the targeted application's data on the Android device. We recommend all users update Play Core to version 1.7.2 or later.
|
|
|
|
### POC
|
|
|
|
#### Reference
|
|
- https://blog.oversecured.com/Oversecured-automatically-discovers-persistent-code-execution-in-the-Google-Play-Core-Library/
|
|
|
|
#### Github
|
|
- https://github.com/0xSojalSec/android-security-resource
|
|
- https://github.com/0xsaju/awesome-android-security
|
|
- https://github.com/ARPSyndicate/cvemon
|
|
- https://github.com/B3nac/Android-Reports-and-Resources
|
|
- https://github.com/CyberLegionLtd/awesome-android-security
|
|
- https://github.com/Live-Hack-CVE/CVE-2020-8913
|
|
- https://github.com/Mehedi-Babu/mobile_sec_cyber
|
|
- https://github.com/Saidul-M-Khan/Awesome-Android-Security
|
|
- https://github.com/Swordfish-Security/awesome-android-security
|
|
- https://github.com/albinjoshy03/4NdrO1D
|
|
- https://github.com/annapustovaya/Mobix
|
|
- https://github.com/ctflearner/Learn365
|
|
- https://github.com/drerx/Android-Reports-and-Resources
|
|
- https://github.com/followboy1999/androidpwn
|
|
- https://github.com/noname1007/awesome-mobile-security
|
|
- https://github.com/paulveillard/cybersecurity-mobile-security
|
|
- https://github.com/rajbhx/Awesome-Android-Security-Clone
|
|
- https://github.com/retr0-13/awesome-android-security
|
|
- https://github.com/saeidshirazi/awesome-android-security
|
|
- https://github.com/son-of-win/Android-pentest
|
|
- https://github.com/vaib25vicky/awesome-mobile-security
|
|
- https://github.com/vickyke1/Android-Reports-and-Resources.
|
|
|