Lucene search

K
cveMitreCVE-2015-4641
HistoryJun 19, 2015 - 2:59 p.m.

CVE-2015-4641

2015-06-1914:59:02
CWE-22
mitre
web.nvd.nist.gov
23
cve-2015-4641
directory traversal
swiftkey
samsung galaxy
vulnerability
update implementation
remote code execution
nvd

CVSS2

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:P/A:P

AI Score

7.7

Confidence

Low

EPSS

0.006

Percentile

79.3%

Directory traversal vulnerability in the SwiftKey language-pack update implementation on Samsung Galaxy S4, S4 Mini, S5, and S6 devices allows remote web servers to write to arbitrary files, and consequently execute arbitrary code in a privileged context, by leveraging control of the skslm.swiftkey.net domain name and providing a … (dot dot) in an entry in a ZIP archive, as demonstrated by a traversal to the /data/dalvik-cache directory.

Affected configurations

Nvd
Node
swiftkeyswiftkey_sdk
AND
samsunggalaxy_s4
OR
samsunggalaxy_s4_mini
OR
samsunggalaxy_s5
OR
samsunggalaxy_s6
VendorProductVersionCPE
swiftkeyswiftkey_sdkcpe:/a:swiftkey:swiftkey_sdk::::

CVSS2

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:P/A:P

AI Score

7.7

Confidence

Low

EPSS

0.006

Percentile

79.3%

Related for CVE-2015-4641