First published: Tue Apr 07 2020(Updated: )
An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), M(6.0), and N(7.0) software. An attacker can obtain the full pathnames of sdcard files by reading the system protected log upon reception of a certain intent. The Samsung ID is SVE-2016-7183 (January 2017).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Android | =4.4 | |
Android | =5.0 | |
Android | =5.1 | |
Android | =6.0 | |
Android | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-18687 has a medium severity rating due to its potential for information exposure.
To fix CVE-2017-18687, update your Samsung mobile device to the latest firmware provided by Samsung.
CVE-2017-18687 affects Android versions 4.4, 5.0, 5.1, 6.0, and 7.0.
While CVE-2017-18687 does not directly cause data loss, it can expose sensitive file information to attackers.
Yes, CVE-2017-18687 is specifically associated with Samsung mobile devices running the affected Android versions.