mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-09 23:27:33 +02:00
778 B
778 B
CVE-2018-8909
Description
The Wire application before 2018-03-07 for Android allows attackers to write to pathnames outside of the downloads directory via a ../ in a filename of a received file, related to AssetService.scala.
POC
Reference
- https://www.x41-dsec.de/reports/X41-Kudelski-Wire-Security-Review-Android.pdf
- https://www.x41-dsec.de/reports/X41-Kudelski-Wire-Security-Review-Android.pdf
Github
No PoCs found on GitHub currently.