[Japanese]

JVNDB-2014-000037

AndExplorer vulnerable to directory traversal

Overview

AndExplorer provided by LYSESOFT contains an issue in processing file names, which may result in a directory traversal (CWE-22) vulnerability.

Ryohei Koike of Sakura Information Systems Co., Ltd. reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
CVSS Severity (What is CVSS?)

Base Metrics: 4.3 (Medium) [IPA Score]
  • Access Vector: Network
  • Access Complexity: Medium
  • Authentication: None
  • Confidentiality Impact: None
  • Integrity Impact: Partial
  • Availability Impact: None

Affected Products


LYSESOFT
  • AndExplorer versions released prior to April 3, 2014
  • AndExplorer Pro versions released prior to April 5, 2014

Impact

A remote, unauthenticated attacker may create an arbitrary file or overwrite an existing file in a directory that the application has privileges to access.
Solution

[Update the software]
Update the software if you are using a version of AndExplorer that was downloaded prior to April 3, 2014 or using a version of AndExplorerPro that was downloaded prior to April 5, 2014.

The software version that is downloaded will differ depending on the version of Android OS that you are using.
Vendor Information

LYSESOFT
CWE (What is CWE?)

  1. Path Traversal(CWE-22) [IPA Evaluation]
CVE (What is CVE?)

  1. CVE-2014-1974
References

  1. JVN : JVN#22670349
  2. National Vulnerability Database (NVD) : CVE-2014-1974
Revision History

[2014/04/18]
  Web page was published
[2014/04/28]
  References : Content was added