CVE-2018-16268: Medium severity tizen vulnerability
The SoundServer/FocusServer system services in Tizen allow an unprivileged process to perform media-related system actions, due to improper D-Bus security policy configurations. Such actions include playing an arbitrary sound file or DTMF tones. This affects Tizen before 5.0 M1, and Tizen-based firmwares including Samsung Galaxy Gear series before build RE2.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2018-16268?
CVE-2018-16268 is a vulnerability in the SoundServer/FocusServer system services in Tizen that allows an unprivileged process to perform media-related system actions.
What is the severity of CVE-2018-16268?
The severity of CVE-2018-16268 is medium, with a severity value of 4.3.
Which software versions are affected by CVE-2018-16268?
CVE-2018-16268 affects Tizen versions before 5.0 M1.
How can an unprivileged process exploit CVE-2018-16268?
An unprivileged process can exploit CVE-2018-16268 by using improper D-Bus security policy configurations to perform media-related system actions.
Where can I find more information about CVE-2018-16268?
You can find more information about CVE-2018-16268 in the following references: [link1], [link2], [link3].