Page 2 of 12 results (0.007 seconds)

CVSS: 4.3EPSS: 0%CPEs: 17EXPL: 0

The SoundServer/FocusServer system services in Tizen allow an unprivileged process to perform media-related system actions, due to improper D-Bus security policy configurations. Such actions include playing an arbitrary sound file or DTMF tones. This affects Tizen before 5.0 M1, and Tizen-based firmwares including Samsung Galaxy Gear series before build RE2. Los servicios de sistema SoundServer/FocusServer en Tizen, permiten a un proceso no privilegiado llevar a cabo acciones del sistema relacionadas con multimedia, debido a configuraciones de política de seguridad D-Bus inapropiadas. Dichas acciones incluyen la reproducción de un archivo de sonido arbitrario o tonos DTMF. • https://media.defcon.org/DEF%20CON%2026/DEF%20CON%2026%20presentations/Dongsung%20Kim%20and%20Hyoung%20Kee%20Choi%20-%20Updated/DEFCON-26-Dongsung-Kim-and-Hyoung-Kee-Choi-Your-Watch-Can-Watch-You-Updated.pdf https://review.tizen.org/git/?p=platform/core/multimedia/libmm-sound.git%3Ba=commit%3Bh=7fce6f2d6d480b3bd0e84a5ba3f72173a37e36db https://www.youtube.com/watch?v=3IdgBwbOT-g&feature=youtu.be • CWE-269: Improper Privilege Management •

CVSS: 8.1EPSS: 0%CPEs: 17EXPL: 0

The system-popup system service in Tizen allows an unprivileged process to perform popup-related system actions, due to improper D-Bus security policy configurations. Such actions include the triggering system poweroff menu, and prompting a popup with arbitrary strings. This affects Tizen before 5.0 M1, and Tizen-based firmwares including Samsung Galaxy Gear series before build RE2. El servicio de sistema system-popup en Tizen, permite a un proceso no privilegiado llevar a cabo acciones de sistema relacionadas con ventanas emergentes, debido a configuraciones de política de seguridad D-Bus inapropiadas. Dichas acciones incluyen la activación del menú poweroff del sistema y generación de una ventana emergente con cadenas arbitrarias. • https://media.defcon.org/DEF%20CON%2026/DEF%20CON%2026%20presentations/Dongsung%20Kim%20and%20Hyoung%20Kee%20Choi%20-%20Updated/DEFCON-26-Dongsung-Kim-and-Hyoung-Kee-Choi-Your-Watch-Can-Watch-You-Updated.pdf https://review.tizen.org/git/?p=platform/core/system/system-popup.git%3Ba=commit%3Bh=57b3c2f3cd61c6f432e7abe3a2d8b0df72fd4b0e https://www.youtube.com/watch?v=3IdgBwbOT-g&feature=youtu.be • CWE-269: Improper Privilege Management •

CVSS: 6.5EPSS: 0%CPEs: 17EXPL: 0

The bt/bt_core system service in Tizen allows an unprivileged process to create a system user interface and control the Bluetooth pairing process, due to improper D-Bus security policy configurations. This affects Tizen before 5.0 M1, and Tizen-based firmwares including Samsung Galaxy Gear series before build RE2. El servicio de sistema bt/bt_core en Tizen, permite a un proceso no privilegiado crear una interfaz de usuario del sistema y controlar el proceso de emparejamiento de Bluetooth, debido a configuraciones de política de seguridad D-Bus inapropiadas. Esto afecta a Tizen versiones anteriores a 5.0 M1 y a los firmwares basados ??en Tizen, incluyendo la serie Samsung Galaxy Gear versiones anteriores al build RE2. • https://media.defcon.org/DEF%20CON%2026/DEF%20CON%2026%20presentations/Dongsung%20Kim%20and%20Hyoung%20Kee%20Choi%20-%20Updated/DEFCON-26-Dongsung-Kim-and-Hyoung-Kee-Choi-Your-Watch-Can-Watch-You-Updated.pdf https://review.tizen.org/git/?p=platform/core/connectivity/bluetooth-frwk.git%3Ba=commit%3Bh=074dfc9709d8cee84564fc815796b0ef0c3273f5 https://review.tizen.org/git/?p=platform/core/connectivity/bluetooth-frwk.git%3Ba=commit%3Bh=bafbd66906ae5712874dc0d7dd6288d2c1ae4db2 https://www.youtube.com/watch?v=3IdgBwbOT-g&feature=youtu • CWE-269: Improper Privilege Management •

CVSS: 6.5EPSS: 0%CPEs: 17EXPL: 0

The BlueZ system service in Tizen allows an unprivileged process to partially control Bluetooth or acquire sensitive information, due to improper D-Bus security policy configurations. This affects Tizen before 5.0 M1, and Tizen-based firmwares including Samsung Galaxy Gear series before build RE2. El servicio de sistema BlueZ en Tizen, permite a un proceso no privilegiado controlar parcialmente Bluetooth o adquirir información confidencial, debido a configuraciones de política de seguridad D-Bus inapropiadas. Esto afecta a Tizen versiones anteriores a 5.0 M1 y a los firmwares basados ??en Tizen, incluyendo la serie Samsung Galaxy Gear versiones anteriores al build RE2. • https://media.defcon.org/DEF%20CON%2026/DEF%20CON%2026%20presentations/Dongsung%20Kim%20and%20Hyoung%20Kee%20Choi%20-%20Updated/DEFCON-26-Dongsung-Kim-and-Hyoung-Kee-Choi-Your-Watch-Can-Watch-You-Updated.pdf https://review.tizen.org/git/?p=platform/upstream/bluez.git%3Ba=commit%3Bh=ff9878c95efc12d4a4495153ab51e3a09f8d3c01 https://www.youtube.com/watch?v=3IdgBwbOT-g&feature=youtu.be • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 8.8EPSS: 0%CPEs: 17EXPL: 0

The PulseAudio system service in Tizen allows an unprivileged process to control its A2DP MediaEndpoint, due to improper D-Bus security policy configurations. This affects Tizen before 5.0 M1, and Tizen-based firmwares including Samsung Galaxy Gear series before build RE2. El servicio de sistema PulseAudio en Tizen permite a un proceso no privilegiado controlar su A2DP MediaEndpoint, debido a configuraciones incorrectas de la política de seguridad D-Bus. Esto afecta a Tizen versiones anteriores a 5.0 M1 y a los firmwares basados en Tizen, incluyendo la serie Samsung Galaxy Gear versiones anteriores al build RE2. • https://media.defcon.org/DEF%20CON%2026/DEF%20CON%2026%20presentations/Dongsung%20Kim%20and%20Hyoung%20Kee%20Choi%20-%20Updated/DEFCON-26-Dongsung-Kim-and-Hyoung-Kee-Choi-Your-Watch-Can-Watch-You-Updated.pdf https://review.tizen.org/git/?p=platform/upstream/pulseaudio.git%3Ba=commit%3Bh=81e8ba9f3ab0917da4fdfa094f49333be57964c6 https://www.youtube.com/watch?v=3IdgBwbOT-g&feature=youtu.be • CWE-269: Improper Privilege Management •