Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-44128

Опубликовано: 27 сент. 2023
Источник: nvd
CVSS3: 5
CVSS3: 3.6
EPSS Низкий

Описание

he vulnerability is to delete arbitrary files in LGInstallService ("com.lge.lginstallservies") app. The app contains the exported "com.lge.lginstallservies.InstallService" service that exposes an AIDL interface. All its "installPackage*" methods are finally calling the "installPackageVerify()" method that performs signature validation after the delete file method. An attacker can control conditions so this security check is never performed and an attacker-controlled file is deleted.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:google:android:*:*:*:*:*:*:*:*
Версия от 4.0 (включая) до 13.0 (включая)
cpe:2.3:h:lg:v60_thin_q_5g:-:*:*:*:*:*:*:*

EPSS

Процентиль: 5%
0.00022
Низкий

5 Medium

CVSS3

3.6 Low

CVSS3

Дефекты

CWE-367
CWE-367

Связанные уязвимости

CVSS3: 5
github
больше 2 лет назад

he vulnerability is to delete arbitrary files in LGInstallService ("com.lge.lginstallservies") app. The app contains the exported "com.lge.lginstallservies.InstallService" service that exposes an AIDL interface. All its "installPackage*" methods are finally calling the "installPackageVerify()" method that performs signature validation after the delete file method. An attacker can control conditions so this security check is never performed and an attacker-controlled file is deleted.

EPSS

Процентиль: 5%
0.00022
Низкий

5 Medium

CVSS3

3.6 Low

CVSS3

Дефекты

CWE-367
CWE-367