Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2014-1423

Опубликовано: 07 мая 2020
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 4.3
CVSS3: 5.9

Описание

signond before 8.57+15.04.20141127.1-0ubuntu1, as used in Ubuntu Touch, did not properly restrict applications from querying oath tokens due to incorrect checks and the missing installation of the signon-apparmor-extension. An attacker could use this create a malicious click app that collects oauth tokens for other applications, exposing sensitive information.

РелизСтатусПримечание
artful

released

8.57+15.04.20141127.1-0ubuntu1
bionic

released

8.57+15.04.20141127.1-0ubuntu1
cosmic

released

8.57+15.04.20141127.1-0ubuntu1
devel

released

8.57+15.04.20141127.1-0ubuntu1
disco

released

8.57+15.04.20141127.1-0ubuntu1
esm-apps/bionic

released

8.57+15.04.20141127.1-0ubuntu1
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was needed]
esm-infra/xenial

released

8.57+15.04.20141127.1-0ubuntu1
lucid

DNE

precise

DNE

Показывать по

Ссылки на источники

EPSS

Процентиль: 43%
0.00207
Низкий

4.3 Medium

CVSS2

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
nvd
больше 5 лет назад

signond before 8.57+15.04.20141127.1-0ubuntu1, as used in Ubuntu Touch, did not properly restrict applications from querying oath tokens due to incorrect checks and the missing installation of the signon-apparmor-extension. An attacker could use this create a malicious click app that collects oauth tokens for other applications, exposing sensitive information.

github
больше 3 лет назад

signond before 8.57+15.04.20141127.1-0ubuntu1, as used in Ubuntu Touch, did not properly restrict applications from querying oath tokens due to incorrect checks and the missing installation of the signon-apparmor-extension. An attacker could use this create a malicious click app that collects oauth tokens for other applications, exposing sensitive information.

EPSS

Процентиль: 43%
0.00207
Низкий

4.3 Medium

CVSS2

5.9 Medium

CVSS3