[Japanese]

JVNDB-2014-000035

SD Card Manager vulnerable to directory traversal

Overview

SD Card Manager provided by apps4u@android contains an issue in processing file names, which may result in a directory traversal (CWE-22) vulnerability.

Ryohei Koike of Sakura Information Systems Co., Ltd. reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
CVSS Severity (What is CVSS?)

Base Metrics: 4.3 (Medium) [IPA Score]
  • Access Vector: Network
  • Access Complexity: Medium
  • Authentication: None
  • Confidentiality Impact: None
  • Integrity Impact: Partial
  • Availability Impact: None

Affected Products


apps4u@android
  • SD Card Manager

All versions released prior to February 24, 2014 are affected
Impact

A remote, unauthenticated attacker may create an arbitrary file or overwrite an existing file in a directory that the application has privileges to access.
Solution

[Apply an Update]
Update the software if you are using a version that was downloaded prior to February 24, 2014.

The software version that is downloaded will differ depending on the version of Android OS that you are using.

According to the developer, SD Card Manager 2.5.6 for Android 3.2 will not have this vulnerability addressed.
Vendor Information

apps4u@android
CWE (What is CWE?)

  1. Path Traversal(CWE-22) [IPA Evaluation]
CVE (What is CVE?)

  1. CVE-2014-1969
References

  1. JVN : JVN#47386847
  2. National Vulnerability Database (NVD) : CVE-2014-1969
Revision History

[2014/04/11]
  Web page was published
[2014/04/16]
  References : Content was added