CVE-2018-10498: Infoleak
This vulnerability allows local attackers to disclose sensitive information on vulnerable installations of Samsung Email Fixed in version 5.0.02.16. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the handling of file:/// URIs. The issue lies in the lack of proper validation of user-supplied data, which can allow for reading arbitrary files. An attacker can leverage this in conjunction with other vulnerabilities to escalate privileges. Was ZDI-CAN-5329.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-10498?
The severity of CVE-2018-10498 is classified as medium risk.
How do I fix CVE-2018-10498?
To fix CVE-2018-10498, update Samsung Email to version 5.0.02.16 or later.
Who is affected by CVE-2018-10498?
CVE-2018-10498 affects users of Samsung Email prior to version 5.0.02.16.
What kind of information can be disclosed by exploiting CVE-2018-10498?
Exploiting CVE-2018-10498 may allow attackers to disclose sensitive information stored within the Samsung Email application.
What must an attacker do to exploit CVE-2018-10498?
An attacker must first gain the ability to execute low-privileged code on the target system to exploit CVE-2018-10498.