CVE-2015-7888: Path Traversal
Directory traversal vulnerability in the WifiHs20UtilityService on the Samsung S6 Edge LRX22G.G925VVRU1AOE2 allows remote attackers to overwrite or create arbitrary files as the system-level user via a .. (dot dot) in the name of a file, compressed into a zipped file named cred.zip, and downloaded to /sdcard/Download.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-7888?
CVE-2015-7888 is rated as a high severity vulnerability due to its capability to allow remote attackers to overwrite or create arbitrary files.
How do I fix CVE-2015-7888?
To fix CVE-2015-7888, users should update their Samsung Galaxy S6 Edge device firmware to the latest available version that addresses this vulnerability.
What devices are affected by CVE-2015-7888?
CVE-2015-7888 specifically affects the Samsung Galaxy S6 Edge running firmware version g925vvru1aoe2.
What type of vulnerability is CVE-2015-7888?
CVE-2015-7888 is categorized as a directory traversal vulnerability that exploits improper validation of file paths.
Can CVE-2015-7888 be exploited remotely?
Yes, CVE-2015-7888 can be exploited remotely by attackers who manipulate file names to gain unauthorized access to the file system.