Overview
Samsung Galaxy S phones, including the S4 Mini, S4, S5, and S6, fail to properly validate Swiftkey language pack updates.
Description
CWE-345: Insufficient Verification of Data Authenticity - CVE-2015-2865 Samsung Galaxy S phones, including the S4 Mini, S4, S5, and S6, are pre-installed with a version of Swiftkey keyboard that is signed by Samsung to operate with system privileges. By design, Swiftkey periodically checks for language pack updates over HTTP. By intercepting such requests and modifying the necessary fields, an attacker can write arbitrary data to vulnerable devices. |
Impact
A remote, unauthenticated attacker conducting a man-in-the-middle attack may be able to write arbitrary data to vulnerable devices checking for updates. Depending on the frequency of Swiftkey update checks, such an attack may have a low likelihood of occurring. |
Solution
Apply an update |
Avoid untrusted networks |
Vendor Information (Learn More)
Vendor | Status | Date Notified | Date Updated |
---|---|---|---|
Samsung | Affected | 02 Mar 2015 | 16 Jun 2015 |
Samsung Mobile | Unknown | 10 Jun 2015 | 10 Jun 2015 |
If you are a vendor and your product is affected, let us know.
CVSS Metrics (Learn More)
Group | Score | Vector |
---|---|---|
Base | 5.7 | AV:A/AC:M/Au:N/C:N/I:C/A:N |
Temporal | 4.5 | E:POC/RL:OF/RC:C |
Environmental | 4.5 | CDP:N/TD:H/CR:ND/IR:ND/AR:ND |
References
'취약점 정보1' 카테고리의 다른 글
Cisco default credentials - again! (0) | 2015.06.27 |
---|---|
Updates to OpenSSL fix vulnerabilities related to Logjam (0) | 2015.06.17 |
블루코트 ssl취약점 (0) | 2015.06.02 |
Logjam - vulnerabilities in Diffie-Hellman key exchange affect browsers and servers using TLS (0) | 2015.05.21 |
아래한글 임의코드 실행 취약점 보안 업데이트 권고 (0) | 2015.05.21 |