SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2015-4641

Directory traversal vulnerability in the SwiftKey language-pack update implementation on Samsung Galaxy S4, S4 Mini, S5, and S6 devices allows remote web servers to write to arbitrary files, and consequently execute arbitrary code in a privileged…

MEDIUM 6.4EPSS 3.68%

Does this matter?

Lower severity and a low EPSS score (3.68%). Track it; it rarely justifies an emergency change on its own.

Description

Directory traversal vulnerability in the SwiftKey language-pack update implementation on Samsung Galaxy S4, S4 Mini, S5, and S6 devices allows remote web servers to write to arbitrary files, and consequently execute arbitrary code in a privileged context, by leveraging control of the skslm.swiftkey.net domain name and providing a .. (dot dot) in an entry in a ZIP archive, as demonstrated by a traversal to the /data/dalvik-cache directory.

CVSS 2.0
6.4 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:P
EPSS
3.68% probability · 89th percentile
CISA KEV
Not listed
Weakness
CWE-22
Affected
swiftkey/swiftkey sdk
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.