CVE-2015-4641: Path Traversal
Directory traversal vulnerability in the SwiftKey language-pack update implementation on Samsung Galaxy S4, S4 Mini, S5, and S6 devices allows remote web servers to write to arbitrary files, and consequently execute arbitrary code in a privileged context, by leveraging control of the skslm.swiftkey.net domain name and providing a .. (dot dot) in an entry in a ZIP archive, as demonstrated by a traversal to the /data/dalvik-cache directory.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-4641?
CVE-2015-4641 has a high severity rating due to its potential to allow remote code execution.
How do I fix CVE-2015-4641?
To fix CVE-2015-4641, ensure that your SwiftKey app is updated to the latest version that addresses this vulnerability.
Which devices are affected by CVE-2015-4641?
CVE-2015-4641 affects Samsung Galaxy S4, S4 Mini, S5, and S6 devices using SwiftKey.
What type of vulnerability is CVE-2015-4641?
CVE-2015-4641 is a directory traversal vulnerability that allows unauthorized access to system files.
Can CVE-2015-4641 lead to data breaches?
Yes, CVE-2015-4641 can potentially lead to data breaches by allowing remote attackers to execute arbitrary code.