PT-2017-14850 · Mobotap · Dolphin Browser

Benjamin Watson

+1

·

Publicado

2017-12-11

·

Atualizado

2018-01-04

·

CVE-2017-17551

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Mobotap Dolphin Browser for Android version 12.0.2
Description The issue arises from an arbitrary file write vulnerability in the Backup and Restore feature when restoring browser settings from a malicious backup file. This allows an attacker to overwrite a specific executable in the browser's data directory with a crafted malicious executable, which is then executed every time the browser is launched.
Recommendations For Mobotap Dolphin Browser for Android version 12.0.2, as a temporary workaround, consider disabling the Backup and Restore feature until a patch is available. Restrict access to the browser's data directory to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-17551

Produtos afetados

Dolphin Browser