PT-2018-19047 · Google · Android
Publicado
2018-12-06
·
Atualizado
2019-01-02
·
CVE-2018-9554
CVSS v3.1
5.5
Média
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Android versions 7.0 through 8.1
Description
The issue concerns a permissions bypass in the
dumpExtractors function of IMediaExtractor.cp, potentially leading to the disclosure of recently accessed media files. This could result in local information disclosure without requiring additional execution privileges. User interaction is not necessary for exploitation.Recommendations
For Android versions 7.0 through 8.1, consider restricting access to sensitive media files as a temporary mitigation measure until a patch is available.
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Android