Show plain JSON{"dataType": "CVE_RECORD", "containers": {"adp": [{"title": "CVE Program Container", "references": [{"url": "http://android.git.kernel.org/?p=platform/system/netd.git%3Ba=commit%3Bh=79b579c92afc08ab12c0a5788d61f2dd2934836f", "tags": ["x_refsource_CONFIRM", "x_transferred"]}, {"url": "http://android.git.kernel.org/?p=platform/system/core.git%3Ba=commit%3Bh=b620a0b1c7ae486e979826200e8e441605b0a5d6", "tags": ["x_refsource_CONFIRM", "x_transferred"]}, {"url": "http://c-skills.blogspot.com/2011/04/yummy-yummy-gingerbreak.html", "tags": ["x_refsource_MISC", "x_transferred"]}, {"url": "http://androidcommunity.com/gingerbreak-root-for-gingerbread-app-20110421/", "tags": ["x_refsource_MISC", "x_transferred"]}, {"url": "http://android.git.kernel.org/?p=platform/system/vold.git%3Ba=commit%3Bh=c51920c82463b240e2be0430849837d6fdc5352e", "tags": ["x_refsource_CONFIRM", "x_transferred"]}, {"url": "http://xorl.wordpress.com/2011/04/28/android-vold-mpartminors-signedness-issue/", "tags": ["x_refsource_MISC", "x_transferred"]}, {"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/67977", "name": "android-vold-priv-escalation(67977)", "tags": ["vdb-entry", "x_refsource_XF", "x_transferred"]}, {"url": "http://www.androidpolice.com/2011/05/03/google-patches-gingerbreak-exploit-but-dont-worry-we-still-have-root-for-now/", "tags": ["x_refsource_MISC", "x_transferred"]}, {"url": "http://forum.xda-developers.com/showthread.php?t=1044765", "tags": ["x_refsource_MISC", "x_transferred"]}], "providerMetadata": {"orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE", "dateUpdated": "2024-08-06T22:37:25.911Z"}}, {"title": "CISA ADP Vulnrichment", "metrics": [{"cvssV3_1": {"scope": "UNCHANGED", "version": "3.1", "baseScore": 7.8, "attackVector": "LOCAL", "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "integrityImpact": "HIGH", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "HIGH", "privilegesRequired": "LOW", "confidentialityImpact": "HIGH"}}, {"other": {"type": "ssvc", "content": {"id": "CVE-2011-1823", "role": "CISA Coordinator", "options": [{"Exploitation": "active"}, {"Automatable": "no"}, {"Technical Impact": "total"}], "version": "2.0.3", "timestamp": "2025-02-07T14:17:26.875888Z"}}}, {"other": {"type": "kev", "content": {"dateAdded": "2022-09-08", "reference": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2011-1823"}}}], "problemTypes": [{"descriptions": [{"lang": "en", "type": "CWE", "cweId": "CWE-190", "description": "CWE-190 Integer Overflow or Wraparound"}]}], "providerMetadata": {"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2025-02-07T14:17:29.872Z"}, "timeline": [{"lang": "en", "time": "2022-09-08T00:00:00+00:00", "value": "CVE-2011-1823 added to CISA KEV"}]}], "cna": {"affected": [{"vendor": "n/a", "product": "n/a", "versions": [{"status": "affected", "version": "n/a"}]}], "datePublic": "2011-04-21T00:00:00.000Z", "references": [{"url": "http://android.git.kernel.org/?p=platform/system/netd.git%3Ba=commit%3Bh=79b579c92afc08ab12c0a5788d61f2dd2934836f", "tags": ["x_refsource_CONFIRM"]}, {"url": "http://android.git.kernel.org/?p=platform/system/core.git%3Ba=commit%3Bh=b620a0b1c7ae486e979826200e8e441605b0a5d6", "tags": ["x_refsource_CONFIRM"]}, {"url": "http://c-skills.blogspot.com/2011/04/yummy-yummy-gingerbreak.html", "tags": ["x_refsource_MISC"]}, {"url": "http://androidcommunity.com/gingerbreak-root-for-gingerbread-app-20110421/", "tags": ["x_refsource_MISC"]}, {"url": "http://android.git.kernel.org/?p=platform/system/vold.git%3Ba=commit%3Bh=c51920c82463b240e2be0430849837d6fdc5352e", "tags": ["x_refsource_CONFIRM"]}, {"url": "http://xorl.wordpress.com/2011/04/28/android-vold-mpartminors-signedness-issue/", "tags": ["x_refsource_MISC"]}, {"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/67977", "name": "android-vold-priv-escalation(67977)", "tags": ["vdb-entry", "x_refsource_XF"]}, {"url": "http://www.androidpolice.com/2011/05/03/google-patches-gingerbreak-exploit-but-dont-worry-we-still-have-root-for-now/", "tags": ["x_refsource_MISC"]}, {"url": "http://forum.xda-developers.com/showthread.php?t=1044765", "tags": ["x_refsource_MISC"]}], "descriptions": [{"lang": "en", "value": "The vold volume manager daemon on Android 3.0 and 2.x before 2.3.4 trusts messages that are received from a PF_NETLINK socket, which allows local users to execute arbitrary code and gain root privileges via a negative index that bypasses a maximum-only signed integer check in the DirectVolume::handlePartitionAdded method, which triggers memory corruption, as demonstrated by Gingerbreak."}], "problemTypes": [{"descriptions": [{"lang": "en", "type": "text", "description": "n/a"}]}], "providerMetadata": {"orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca", "shortName": "mitre", "dateUpdated": "2017-08-16T14:57:01.000Z"}, "x_legacyV4Record": {"affects": {"vendor": {"vendor_data": [{"product": {"product_data": [{"version": {"version_data": [{"version_value": "n/a"}]}, "product_name": "n/a"}]}, "vendor_name": "n/a"}]}}, "data_type": "CVE", "references": {"reference_data": [{"url": "http://android.git.kernel.org/?p=platform/system/netd.git;a=commit;h=79b579c92afc08ab12c0a5788d61f2dd2934836f", "name": "http://android.git.kernel.org/?p=platform/system/netd.git;a=commit;h=79b579c92afc08ab12c0a5788d61f2dd2934836f", "refsource": "CONFIRM"}, {"url": "http://android.git.kernel.org/?p=platform/system/core.git;a=commit;h=b620a0b1c7ae486e979826200e8e441605b0a5d6", "name": "http://android.git.kernel.org/?p=platform/system/core.git;a=commit;h=b620a0b1c7ae486e979826200e8e441605b0a5d6", "refsource": "CONFIRM"}, {"url": "http://c-skills.blogspot.com/2011/04/yummy-yummy-gingerbreak.html", "name": "http://c-skills.blogspot.com/2011/04/yummy-yummy-gingerbreak.html", "refsource": "MISC"}, {"url": "http://androidcommunity.com/gingerbreak-root-for-gingerbread-app-20110421/", "name": "http://androidcommunity.com/gingerbreak-root-for-gingerbread-app-20110421/", "refsource": "MISC"}, {"url": "http://android.git.kernel.org/?p=platform/system/vold.git;a=commit;h=c51920c82463b240e2be0430849837d6fdc5352e", "name": "http://android.git.kernel.org/?p=platform/system/vold.git;a=commit;h=c51920c82463b240e2be0430849837d6fdc5352e", "refsource": "CONFIRM"}, {"url": "http://xorl.wordpress.com/2011/04/28/android-vold-mpartminors-signedness-issue/", "name": "http://xorl.wordpress.com/2011/04/28/android-vold-mpartminors-signedness-issue/", "refsource": "MISC"}, {"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/67977", "name": "android-vold-priv-escalation(67977)", "refsource": "XF"}, {"url": "http://www.androidpolice.com/2011/05/03/google-patches-gingerbreak-exploit-but-dont-worry-we-still-have-root-for-now/", "name": "http://www.androidpolice.com/2011/05/03/google-patches-gingerbreak-exploit-but-dont-worry-we-still-have-root-for-now/", "refsource": "MISC"}, {"url": "http://forum.xda-developers.com/showthread.php?t=1044765", "name": "http://forum.xda-developers.com/showthread.php?t=1044765", "refsource": "MISC"}]}, "data_format": "MITRE", "description": {"description_data": [{"lang": "eng", "value": "The vold volume manager daemon on Android 3.0 and 2.x before 2.3.4 trusts messages that are received from a PF_NETLINK socket, which allows local users to execute arbitrary code and gain root privileges via a negative index that bypasses a maximum-only signed integer check in the DirectVolume::handlePartitionAdded method, which triggers memory corruption, as demonstrated by Gingerbreak."}]}, "problemtype": {"problemtype_data": [{"description": [{"lang": "eng", "value": "n/a"}]}]}, "data_version": "4.0", "CVE_data_meta": {"ID": "CVE-2011-1823", "STATE": "PUBLIC", "ASSIGNER": "cve@mitre.org"}}}}, "cveMetadata": {"cveId": "CVE-2011-1823", "state": "PUBLISHED", "dateUpdated": "2025-07-28T19:45:05.991Z", "dateReserved": "2011-04-20T00:00:00.000Z", "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca", "datePublished": "2011-06-09T10:00:00.000Z", "assignerShortName": "mitre"}, "dataVersion": "5.1"}