First published: Wed Apr 19 2017(Updated: )
Samsung Android devices with L(5.0/5.1), M(6.0), and N(7.x) software allow attackers to obtain sensitive information by reading a world-readable log file after an unexpected reboot. The Samsung ID is SVE-2017-8290.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Samsung Mobile | =5.0 | |
Samsung Mobile | =5.1 | |
Samsung Mobile | =6.0 | |
Samsung Mobile | =7.0 | |
Samsung Mobile | =7.1 | |
Samsung Mobile | =7.1.1 | |
Samsung Mobile | =7.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-7978 is rated as a medium severity vulnerability due to potential exposure of sensitive information.
To fix CVE-2017-7978, ensure that your Samsung device is updated to the latest software version available.
CVE-2017-7978 affects Samsung Android devices running versions L(5.0/5.1), M(6.0), and N(7.x).
CVE-2017-7978 allows attackers to read sensitive information stored in a world-readable log file.
CVE-2017-7978 occurs after an unexpected reboot of the device, which exposes the log file to unauthorized access.