PT-2018-9919 · Samsung · Samsung Email

Published

2018-06-07

·

Updated

2019-10-09

·

CVE-2018-10498

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Samsung Email versions prior to 5.0.02.16
Description: This issue allows local attackers to disclose sensitive information by exploiting a flaw in the handling of file:/// URIs. The problem stems from the lack of proper validation of user-supplied data, enabling the reading of arbitrary files. An attacker must first obtain the ability to execute low-privileged code on the target system. This issue can be leveraged in conjunction with other vulnerabilities to escalate privileges.
Recommendations: For versions prior to 5.0.02.16, update to version 5.0.02.16 to resolve the issue. As a temporary workaround, consider restricting access to sensitive files and directories to minimize the risk of exploitation.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-10498
ZDI-18-557

Affected Products

Samsung Email