CVE-2018-16266: High severity tizen vulnerability
The Enlightenment system service in Tizen allows an unprivileged process to fully control or capture windows, due to improper D-Bus security policy configurations. This affects Tizen before 5.0 M1, and Tizen-based firmwares including Samsung Galaxy Gear series before build RE2.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID?
CVE-2018-16266
What is the severity of CVE-2018-16266?
The severity of CVE-2018-16266 is high with a severity value of 8.1.
How does CVE-2018-16266 affect Tizen-based firmwares?
CVE-2018-16266 affects Tizen-based firmwares including Samsung Galaxy Gear series before build RE2.
How can an unprivileged process fully control or capture windows in Tizen?
An unprivileged process can fully control or capture windows in Tizen due to improper D-Bus security policy configurations.
Are there any references available for CVE-2018-16266?
Yes, you can refer to the following links for more information on CVE-2018-16266: [Link 1](https://media.defcon.org/DEF%20CON%2026/DEF%20CON%2026%20presentations/Dongsung%20Kim%20and%20Hyoung%20Kee%20Choi%20-%20Updated/DEFCON-26-Dongsung-Kim-and-Hyoung-Kee-Choi-Your-Watch-Can-Watch-You-Updated.pdf), [Link 2](https://review.tizen.org/git/?p=platform/upstream/enlightenment.git;a=commit;h=8ff5c24d04f97b1c84b463535876600b22128fb4), [Link 3](https://www.youtube.com/watch?v=3IdgBwbOT-g&feature=youtu.be)