Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2019-0932

Опубликовано: 14 мая 2019
Источник: msrc
EPSS Низкий

Описание

Skype for Android Information Disclosure Vulnerability

An information disclosure vulnerability exists in Skype for Android. An attacker that exploited the vulnerability could listen to the conversation of a Skype for Android user without the user’s knowledge.

To exploit the vulnerability, an attacker would need to call an Android phone with Skype for Android installed that’s also paired with a Bluetooth device.

The security update addresses the vulnerability by correcting how Skype for Android answers incoming calls.

FAQ

What type of information could be disclosed by this vulnerability?

The type of information that could be disclosed if an attacker successfully exploited this vulnerability is audio from a cellular phone call.

How do I get the update for Skype for Android?

  1. Tap the Google Play icon on your home screen.
  2. Swipe in from the left edge of the screen.
  3. Tap My apps & games.
  4. Tap the Update box next to the Skype app.

Возможность эксплуатации

Publicly Disclosed

Yes

Exploited

No

Latest Software Release

Exploitation Less Likely

Older Software Release

Exploitation Less Likely

EPSS

Процентиль: 88%
0.03923
Низкий

Связанные уязвимости

CVSS3: 5.9
nvd
больше 6 лет назад

An information disclosure vulnerability exists in Skype for Android, aka 'Skype for Android Information Disclosure Vulnerability'.

github
больше 3 лет назад

An information disclosure vulnerability exists in Skype for Android, aka 'Skype for Android Information Disclosure Vulnerability'.

CVSS3: 5.9
fstec
больше 6 лет назад

Уязвимость программы мгновенного обмена сообщениями Skype для операционных систем Android, позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 88%
0.03923
Низкий