CVE-2022-28791: Input Validation
Published May 3, 2022
·Updated
Improper input validation vulnerability in InstallAgent in Galaxy Store prior to version 4.5.41.8 allows attacker to overwrite files stored in a specific path. The patch adds proper protection to prevent overwrite to existing files.
Affected Software
1 affected component
Samsung Galaxy Store<4.5.41.8
Event History
May 3, 2022
CVE Published
via MITRE·07:43 PM
Data Sourced
via MITRE·07:43 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-28791?
CVE-2022-28791 has a high severity due to its potential for unauthorized file overwrites.
2
How do I fix CVE-2022-28791?
To fix CVE-2022-28791, update the Galaxy Store to version 4.5.41.8 or later.
3
What impact does CVE-2022-28791 have on affected systems?
CVE-2022-28791 allows an attacker to overwrite files, which can compromise the integrity and security of the system.
4
Which versions of Galaxy Store are affected by CVE-2022-28791?
CVE-2022-28791 affects all versions of Galaxy Store prior to 4.5.41.8.
5
What measures were taken to resolve CVE-2022-28791?
The resolution for CVE-2022-28791 involves implementing proper input validation to prevent file overwriting.