First published: Fri Aug 31 2012(Updated: )
The Cybozu Live application 1.0.4 and earlier for Android allows remote attackers to execute arbitrary Java methods, and obtain sensitive information or execute arbitrary commands, via a crafted web site.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Cybozu Live | <=1.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-4008 is classified as a critical vulnerability due to its potential to allow remote code execution and exposure of sensitive information.
To fix CVE-2012-4008, upgrade the Cybozu Live application to version 1.0.5 or later.
The potential impacts of CVE-2012-4008 include unauthorized access to sensitive data and the ability to execute arbitrary commands on the affected device.
CVE-2012-4008 affects users of the Cybozu Live application version 1.0.4 and earlier on Android devices.
Yes, CVE-2012-4008 can be exploited remotely through a crafted website.