CVE-2015-4641
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
4Exploited in Wild
-Decision
Descriptions
Directory traversal vulnerability in the SwiftKey language-pack update implementation on Samsung Galaxy S4, S4 Mini, S5, and S6 devices allows remote web servers to write to arbitrary files, and consequently execute arbitrary code in a privileged context, by leveraging control of the skslm.swiftkey.net domain name and providing a .. (dot dot) in an entry in a ZIP archive, as demonstrated by a traversal to the /data/dalvik-cache directory.
Vulnerabilidad de salto de directorio en la implementación de la actualización del paquete de lenguas SwiftKey en los dispositivos Samsung Galaxy S4, S4 Mini, S5, y S6 permite servidores web remotos escribir en ficheros arbitrarios, y como consecuencia ejecutar código arbitrario en un contexto privilegiado, mediante el aprovechamiento del control del nombre de dominio skslm.swiftkey.net y la provisión de un .. (punto punto) en una entrada en un archivo ZIP, tal y como fue demostrado por un salto en el directorio /data/dalvik-cache.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2015-06-17 CVE Reserved
- 2015-06-19 CVE Published
- 2024-08-06 CVE Updated
- 2024-08-06 First Exploit
- 2024-10-23 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
http://www.kb.cert.org/vuls/id/155412 | Third Party Advisory | |
http://www.securityfocus.com/bid/75353 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Swiftkey Search vendor "Swiftkey" | Swiftkey Sdk Search vendor "Swiftkey" for product "Swiftkey Sdk" | * | - |
Affected
| in | Samsung Search vendor "Samsung" | Galaxy S4 Search vendor "Samsung" for product "Galaxy S4" | * | - |
Safe
|
Swiftkey Search vendor "Swiftkey" | Swiftkey Sdk Search vendor "Swiftkey" for product "Swiftkey Sdk" | * | - |
Affected
| in | Samsung Search vendor "Samsung" | Galaxy S4 Mini Search vendor "Samsung" for product "Galaxy S4 Mini" | * | - |
Safe
|
Swiftkey Search vendor "Swiftkey" | Swiftkey Sdk Search vendor "Swiftkey" for product "Swiftkey Sdk" | * | - |
Affected
| in | Samsung Search vendor "Samsung" | Galaxy S5 Search vendor "Samsung" for product "Galaxy S5" | * | - |
Safe
|
Swiftkey Search vendor "Swiftkey" | Swiftkey Sdk Search vendor "Swiftkey" for product "Swiftkey Sdk" | * | - |
Affected
| in | Samsung Search vendor "Samsung" | Galaxy S6 Search vendor "Samsung" for product "Galaxy S6" | * | - |
Safe
|