The wemail_consumer_service (from the built-in application wemail) in Samsung Galaxy Gear series allows an unprivileged process to manipulate a user's mailbox, due to improper D-Bus security policy configurations. An arbitrary email can also be sent from the mailbox via the paired smartphone. This affects Tizen-based firmwares including Samsung Galaxy Gear series before build RE2.
References
Link | Resource |
---|---|
https://media.defcon.org/DEF%20CON%2026/DEF%20CON%2026%20presentations/Dongsung%20Kim%20and%20Hyoung%20Kee%20Choi%20-%20Updated/DEFCON-26-Dongsung-Kim-and-Hyoung-Kee-Choi-Your-Watch-Can-Watch-You-Updated.pdf | Exploit Third Party Advisory |
https://www.youtube.com/watch?v=3IdgBwbOT-g&feature=youtu.be | Exploit Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2020-01-22T13:03:26
Updated: 2020-01-22T13:03:26
Reserved: 2018-08-31T00:00:00
Link: CVE-2018-16271
JSON object: View
NVD Information
Status : Analyzed
Published: 2020-01-22T14:15:11.277
Modified: 2020-01-30T17:51:05.517
Link: CVE-2018-16271
JSON object: View
Redhat Information
No data.
CWE