PT-2014-8649 · Google · Android

Publicado

2014-12-15

·

Atualizado

2014-12-16

·

CVE-2014-8609

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Android versions prior to 5.0.0
Description The issue concerns the addAccount method in the Settings application, which does not properly create a PendingIntent. This allows attackers to broadcast an intent with arbitrary component, action, or category information using a third-party authenticator in a crafted application.
Recommendations For Android versions prior to 5.0.0, update to version 5.0.0 or later to resolve the issue.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-8609

Produtos afetados

Android