Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vrvp-9jr4-5gp9

Опубликовано: 27 сент. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 5

Описание

he vulnerability is to delete arbitrary files in LGInstallService ("com.lge.lginstallservies") app. The app contains the exported "com.lge.lginstallservies.InstallService" service that exposes an AIDL interface. All its "installPackage*" methods are finally calling the "installPackageVerify()" method that performs signature validation after the delete file method. An attacker can control conditions so this security check is never performed and an attacker-controlled file is deleted.

he vulnerability is to delete arbitrary files in LGInstallService ("com.lge.lginstallservies") app. The app contains the exported "com.lge.lginstallservies.InstallService" service that exposes an AIDL interface. All its "installPackage*" methods are finally calling the "installPackageVerify()" method that performs signature validation after the delete file method. An attacker can control conditions so this security check is never performed and an attacker-controlled file is deleted.

EPSS

Процентиль: 5%
0.00022
Низкий

5 Medium

CVSS3

Дефекты

CWE-367

Связанные уязвимости

CVSS3: 5
nvd
больше 2 лет назад

he vulnerability is to delete arbitrary files in LGInstallService ("com.lge.lginstallservies") app. The app contains the exported "com.lge.lginstallservies.InstallService" service that exposes an AIDL interface. All its "installPackage*" methods are finally calling the "installPackageVerify()" method that performs signature validation after the delete file method. An attacker can control conditions so this security check is never performed and an attacker-controlled file is deleted.

EPSS

Процентиль: 5%
0.00022
Низкий

5 Medium

CVSS3

Дефекты

CWE-367