Direct naar de inhoud
Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
cybernieuws.nl Cybersecurity en informatiebeveiling nieuws alerts live · 4 min 110 bronnen 3 kritiek 24 vandaag
CVE's Videos

← Terug naar CVE-database

CVE-2015-4641

MEDIUM · 6.4 CVSS Gepubliceerd: CWE-22

Beschrijving

Directory traversal vulnerability in the SwiftKey language-pack update implementation on Samsung Galaxy S4, S4 Mini, S5, and S6 devices allows remote web servers to write to arbitrary files, and consequently execute arbitrary code in a privileged context, by leveraging control of the skslm.swiftkey.net domain name and providing a .. (dot dot) in an entry in a ZIP archive, as demonstrated by a traversal to the /data/dalvik-cache directory.

Vendors

Swiftkey Samsung

Affected products

Swiftkey Sdk Galaxy S4 Galaxy S4 Mini Galaxy S5 Galaxy S6

References