Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m288-pv5h-3xf6

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The addAccount method in src/com/android/settings/accounts/AddAccountSettings.java in the Settings application in Android before 5.0.0 does not properly create a PendingIntent, which allows attackers to use the SYSTEM uid for broadcasting an intent with arbitrary component, action, or category information via a third-party authenticator in a crafted application, aka Bug 17356824.

The addAccount method in src/com/android/settings/accounts/AddAccountSettings.java in the Settings application in Android before 5.0.0 does not properly create a PendingIntent, which allows attackers to use the SYSTEM uid for broadcasting an intent with arbitrary component, action, or category information via a third-party authenticator in a crafted application, aka Bug 17356824.

EPSS

Процентиль: 64%
0.00473
Низкий

Связанные уязвимости

nvd
около 11 лет назад

The addAccount method in src/com/android/settings/accounts/AddAccountSettings.java in the Settings application in Android before 5.0.0 does not properly create a PendingIntent, which allows attackers to use the SYSTEM uid for broadcasting an intent with arbitrary component, action, or category information via a third-party authenticator in a crafted application, aka Bug 17356824.

EPSS

Процентиль: 64%
0.00473
Низкий