First published: Fri Oct 05 2018(Updated: )
The 1Password application 6.8 for Android is affected by a Denial Of Service vulnerability. By starting the activity com.agilebits.onepassword.filling.openyolo.OpenYoloDeleteActivity or com.agilebits.onepassword.filling.openyolo.OpenYoloRetrieveActivity from an external application (since they are exported), it is possible to crash the 1Password instance.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
1Password | =6.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-13042 has been classified as a Denial of Service vulnerability.
To fix CVE-2018-13042, update the 1Password application to a later version than 6.8.
CVE-2018-13042 affects version 6.8 of the 1Password application on Android.
CVE-2018-13042 can cause Denial of Service, potentially preventing users from accessing the 1Password application.
Yes, CVE-2018-13042 can be exploited by starting specific activities from an external application.