CVE-2017-7978: Infoleak
Samsung Android devices with L(5.0/5.1), M(6.0), and N(7.x) software allow attackers to obtain sensitive information by reading a world-readable log file after an unexpected reboot. The Samsung ID is SVE-2017-8290.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
For Samsung Android devices affected by SVE-2017-8290 (L 5.0/5.1, M 6.0, N 7.x), prevent access to the world-readable log file by restricting who can read logs (e.g., adjust system permissions or access controls so the log is no longer world-readable after an unexpected reboot).
Event History
Frequently Asked Questions
What is the severity of CVE-2017-7978?
CVE-2017-7978 is rated as a medium severity vulnerability due to potential exposure of sensitive information.
How do I fix CVE-2017-7978?
To fix CVE-2017-7978, ensure that your Samsung device is updated to the latest software version available.
Which devices are affected by CVE-2017-7978?
CVE-2017-7978 affects Samsung Android devices running versions L(5.0/5.1), M(6.0), and N(7.x).
What type of information can be compromised in CVE-2017-7978?
CVE-2017-7978 allows attackers to read sensitive information stored in a world-readable log file.
What causes CVE-2017-7978 to occur?
CVE-2017-7978 occurs after an unexpected reboot of the device, which exposes the log file to unauthorized access.