CVE-2013-4787
Summary
| CVE | CVE-2013-4787 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2013-07-09 17:55:01 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Android 1.6 Donut through 4.2 Jelly Bean does not properly check cryptographic signatures for applications, which allows attackers to execute arbitrary code via an application package file (APK) that is modified in a way that does not violate the cryptographic signature, probably involving multiple entries in a Zip file with the same name in which one entry is validated but the other entry is installed, aka Android security bug 8219321 and the "Master Key" vulnerability. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:M/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Android | 1.6 | All | All | All | |
| Operating System | Android | 2.0 | All | All | All | |
| Operating System | Android | 2.0.1 | All | All | All | |
| Operating System | Android | 2.1 | All | All | All | |
| Operating System | Android | 2.2 | All | All | All | |
| Operating System | Android | 2.2 | rev1 | All | All | |
| Operating System | Android | 2.2.1 | All | All | All | |
| Operating System | Android | 2.2.2 | All | All | All | |
| Operating System | Android | 2.2.3 | All | All | All | |
| Operating System | Android | 2.3 | All | All | All | |
| Operating System | Android | 2.3 | rev1 | All | All | |
| Operating System | Android | 2.3.1 | All | All | All | |
| Operating System | Android | 2.3.2 | All | All | All | |
| Operating System | Android | 2.3.3 | All | All | All | |
| Operating System | Android | 2.3.4 | All | All | All | |
| Operating System | Android | 2.3.5 | All | All | All | |
| Operating System | Android | 2.3.6 | All | All | All | |
| Operating System | Android | 2.3.7 | All | All | All | |
| Operating System | Android | 3.0 | All | All | All | |
| Operating System | Android | 3.1 | All | All | All | |
| Operating System | Android | 3.2 | All | All | All | |
| Operating System | Android | 3.2.1 | All | All | All | |
| Operating System | Android | 3.2.2 | All | All | All | |
| Operating System | Android | 3.2.4 | All | All | All | |
| Operating System | Android | 3.2.6 | All | All | All | |
| Operating System | Android | 4.0 | All | All | All | |
| Operating System | Android | 4.0.1 | All | All | All | |
| Operating System | Android | 4.0.2 | All | All | All | |
| Operating System | Android | 4.0.3 | All | All | All | |
| Operating System | Android | 4.0.4 | All | All | All | |
| Operating System | Android | 4.1 | All | All | All | |
| Operating System | Android | 4.1.2 | All | All | All | |
| Operating System | Android | 4.2 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Google Android 'APK' code Remote Security Bypass Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| www.osvdb.org/94773 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| [#CYAN-1602] Patch for Android bug security bug 8219321? - CyanogenMod JIRA | af854a3a-2127-422b-91ae-364da2661108 | jira.cyanogenmod.org | |
| Sign in - Google Accounts | af854a3a-2127-422b-91ae-364da2661108 | plus.google.com | |
| Uncovering Android Master Key That Makes 99% of Devices Vulnerable » Bluebox Security | af854a3a-2127-422b-91ae-364da2661108 | bluebox.com | |
| Google releases fix to OEMs for Blue Security Android security hole | ZDNet | af854a3a-2127-422b-91ae-364da2661108 | www.zdnet.com | |
| Gerrit Code Review | af854a3a-2127-422b-91ae-364da2661108 | review.cyanogenmod.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.