CVE-2018-13042: Input Validation
The 1Password application 6.8 for Android is affected by a Denial Of Service vulnerability. By starting the activity com.agilebits.onepassword.filling.openyolo.OpenYoloDeleteActivity or com.agilebits.onepassword.filling.openyolo.OpenYoloRetrieveActivity from an external application (since they are exported), it is possible to crash the 1Password instance.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-13042?
CVE-2018-13042 has been classified as a Denial of Service vulnerability.
How do I fix CVE-2018-13042?
To fix CVE-2018-13042, update the 1Password application to a later version than 6.8.
What versions of 1Password are affected by CVE-2018-13042?
CVE-2018-13042 affects version 6.8 of the 1Password application on Android.
What impact does CVE-2018-13042 have on mobile devices?
CVE-2018-13042 can cause Denial of Service, potentially preventing users from accessing the 1Password application.
Can CVE-2018-13042 be exploited remotely?
Yes, CVE-2018-13042 can be exploited by starting specific activities from an external application.