CVE-2018-16267: High severity tizen vulnerability
The system-popup system service in Tizen allows an unprivileged process to perform popup-related system actions, due to improper D-Bus security policy configurations. Such actions include the triggering system poweroff menu, and prompting a popup with arbitrary strings. This affects Tizen before 5.0 M1, and Tizen-based firmwares including Samsung Galaxy Gear series before build RE2.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2018-16267?
CVE-2018-16267 is a vulnerability in the Tizen operating system that allows an unprivileged process to perform popup-related system actions.
What is the severity of CVE-2018-16267?
CVE-2018-16267 has a severity rating of 8.1 (high).
How does CVE-2018-16267 affect Tizen?
CVE-2018-16267 affects Tizen versions before 5.0.
What actions can an attacker perform with CVE-2018-16267?
An attacker can trigger the system poweroff menu and prompt a popup with arbitrary strings using CVE-2018-16267.
How can I fix CVE-2018-16267?
To fix CVE-2018-16267, update your Tizen operating system to version 5.0 or a higher version.