CVE-2013-3685
Summary
| CVE | CVE-2013-3685 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-02-12 16:15:00 UTC |
| Updated | 2020-02-19 19:43:00 UTC |
| Description | A Privilege Escalation Vulnerability exists in Sprite Software Spritebud 1.3.24 and 1.3.28 and Backup 2.5.4105 and 2.5.4108 on LG Android smartphones due to a race condition in the spritebud daemon, which could let a local malicious user obtain root privileges. |
Risk And Classification
Problem Types: CWE-362
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Lg | E971 | - | All | All | All |
| Hardware | Lg | E971 | - | All | All | All |
| Hardware | Lg | E973 | - | All | All | All |
| Hardware | Lg | E973 | - | All | All | All |
| Hardware | Lg | E975 | - | All | All | All |
| Hardware | Lg | E975 | - | All | All | All |
| Hardware | Lg | E975k | - | All | All | All |
| Hardware | Lg | E975k | - | All | All | All |
| Hardware | Lg | E975t | - | All | All | All |
| Hardware | Lg | E975t | - | All | All | All |
| Hardware | Lg | E976 | - | All | All | All |
| Hardware | Lg | E976 | - | All | All | All |
| Hardware | Lg | E977 | - | All | All | All |
| Hardware | Lg | E977 | - | All | All | All |
| Hardware | Lg | F100k | - | All | All | All |
| Hardware | Lg | F100k | - | All | All | All |
| Hardware | Lg | F100l | - | All | All | All |
| Hardware | Lg | F100l | - | All | All | All |
| Hardware | Lg | F100s | - | All | All | All |
| Hardware | Lg | F100s | - | All | All | All |
| Hardware | Lg | F120k | - | All | All | All |
| Hardware | Lg | F120k | - | All | All | All |
| Hardware | Lg | F120l | - | All | All | All |
| Hardware | Lg | F120l | - | All | All | All |
| Hardware | Lg | F120s | - | All | All | All |
| Hardware | Lg | F120s | - | All | All | All |
| Hardware | Lg | F160k | - | All | All | All |
| Hardware | Lg | F160k | - | All | All | All |
| Hardware | Lg | F160l | - | All | All | All |
| Hardware | Lg | F160l | - | All | All | All |
| Hardware | Lg | F160lv | - | All | All | All |
| Hardware | Lg | F160lv | - | All | All | All |
| Hardware | Lg | F160s | - | All | All | All |
| Hardware | Lg | F160s | - | All | All | All |
| Hardware | Lg | F180k | - | All | All | All |
| Hardware | Lg | F180k | - | All | All | All |
| Hardware | Lg | F180l | - | All | All | All |
| Hardware | Lg | F180l | - | All | All | All |
| Hardware | Lg | F180s | - | All | All | All |
| Hardware | Lg | F180s | - | All | All | All |
| Hardware | Lg | F200k | - | All | All | All |
| Hardware | Lg | F200k | - | All | All | All |
| Hardware | Lg | F200l | - | All | All | All |
| Hardware | Lg | F200l | - | All | All | All |
| Hardware | Lg | F200s | - | All | All | All |
| Hardware | Lg | F200s | - | All | All | All |
| Hardware | Lg | F240k | - | All | All | All |
| Hardware | Lg | F240k | - | All | All | All |
| Hardware | Lg | F240l | - | All | All | All |
| Hardware | Lg | F240l | - | All | All | All |
| Hardware | Lg | F240s | - | All | All | All |
| Hardware | Lg | F240s | - | All | All | All |
| Hardware | Lg | F260k | - | All | All | All |
| Hardware | Lg | F260k | - | All | All | All |
| Hardware | Lg | F260l | - | All | All | All |
| Hardware | Lg | F260l | - | All | All | All |
| Hardware | Lg | F260s | - | All | All | All |
| Hardware | Lg | F260s | - | All | All | All |
| Hardware | Lg | L21 | - | All | All | All |
| Hardware | Lg | L21 | - | All | All | All |
| Hardware | Lg | Lg870 | - | All | All | All |
| Hardware | Lg | Lg870 | - | All | All | All |
| Hardware | Lg | Ls860 | - | All | All | All |
| Hardware | Lg | Ls860 | - | All | All | All |
| Hardware | Lg | Ls970 | - | All | All | All |
| Hardware | Lg | Ls970 | - | All | All | All |
| Hardware | Lg | P760 | - | All | All | All |
| Hardware | Lg | P760 | - | All | All | All |
| Hardware | Lg | P769 | - | All | All | All |
| Hardware | Lg | P769 | - | All | All | All |
| Hardware | Lg | P780 | - | All | All | All |
| Hardware | Lg | P780 | - | All | All | All |
| Hardware | Lg | P875 | - | All | All | All |
| Hardware | Lg | P875 | - | All | All | All |
| Hardware | Lg | P875h | - | All | All | All |
| Hardware | Lg | P875h | - | All | All | All |
| Hardware | Lg | P880 | - | All | All | All |
| Hardware | Lg | P880 | - | All | All | All |
| Hardware | Lg | P940 | - | All | All | All |
| Hardware | Lg | P940 | - | All | All | All |
| Hardware | Lg | Su540 | - | All | All | All |
| Hardware | Lg | Su540 | - | All | All | All |
| Hardware | Lg | Su870 | - | All | All | All |
| Hardware | Lg | Su870 | - | All | All | All |
| Hardware | Lg | Us780 | - | All | All | All |
| Hardware | Lg | Us780 | - | All | All | All |
| Application | Spritesoftware | Spritebackup | 2.5.4105 | All | All | All |
| Application | Spritesoftware | Spritebackup | 2.5.4108 | All | All | All |
| Application | Spritesoftware | Spritebackup | 2.5.4105 | All | All | All |
| Application | Spritesoftware | Spritebackup | 2.5.4108 | All | All | All |
| Application | Spritesoftware | Spritebud | 1.3.24 | All | All | All |
| Application | Spritesoftware | Spritebud | 1.3.28 | All | All | All |
| Application | Spritesoftware | Spritebud | 1.3.24 | All | All | All |
| Application | Spritesoftware | Spritebud | 1.3.28 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| All vulnerabilities - Android Vulnerabilities | MISC | androidvulnerabilities.org | Third Party Advisory |
| Full Disclosure: CVE-2013-3685: Root exploit for LG Android devices (target sprite software's backup daemon) | MISC | seclists.org | Exploit, Mailing List, Third Party Advisory |
| IBM X-Force Exchange | MISC | exchange.xforce.ibmcloud.com | Third Party Advisory, VDB Entry |
| Multiple Sprite Software Products for LG Android Devices Local Privilege Escalation Vulnerability | MISC | www.securityfocus.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.