mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-13 22:32:09 +02:00
18 lines
697 B
Markdown
18 lines
697 B
Markdown
### [CVE-2018-8909](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-8909)
|
|

|
|

|
|

|
|
|
|
### Description
|
|
|
|
The Wire application before 2018-03-07 for Android allows attackers to write to pathnames outside of the downloads directory via a ../ in a filename of a received file, related to AssetService.scala.
|
|
|
|
### POC
|
|
|
|
#### Reference
|
|
- https://www.x41-dsec.de/reports/X41-Kudelski-Wire-Security-Review-Android.pdf
|
|
|
|
#### Github
|
|
No PoCs found on GitHub currently.
|
|
|