PT-2018-9919 · Samsung · Samsung Email

Publicado

2018-06-07

·

Atualizado

2019-10-09

·

CVE-2018-10498

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Samsung Email versions prior to 5.0.02.16
Description: This issue allows local attackers to disclose sensitive information by exploiting a flaw in the handling of file:/// URIs. The problem stems from the lack of proper validation of user-supplied data, enabling the reading of arbitrary files. An attacker must first obtain the ability to execute low-privileged code on the target system. This issue can be leveraged in conjunction with other vulnerabilities to escalate privileges.
Recommendations: For versions prior to 5.0.02.16, update to version 5.0.02.16 to resolve the issue. As a temporary workaround, consider restricting access to sensitive files and directories to minimize the risk of exploitation.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-10498
ZDI-18-557

Produtos afetados

Samsung Email