[Japanese]

JVNDB-2005-000764

Website connection problem when a mobile phone terminal uses specific QR code

Overview

Mobile phone terminals supporting the two-dimensional code (QR code) read function are reported to have a website connection problem. When specific QR code is read, even if a user tries to connect to the URL string in the first line of the two URL lines displayed, the connection is established with the second URL.

This problem has been reported for KDDI mobile phones. The developer provides countermeasure information although they judged this problem not a vulnerability. JVN has publicized this issue in coordination with the developer to make it known to users.
CVSS Severity (What is CVSS?)

CVSS V2 Severity:
Base Metrics 4.3 (Medium) [IPA Score]
  • Access Vector: Network
  • Access Complexity: Medium
  • Authentication: None
  • Confidentiality Impact: None
  • Integrity Impact: Partial
  • Availability Impact: None
Affected Products


KDDI
  • Barcode Reader (two dimension)

Impact

When specific QR code is read, connection could be established with an unintended site (the site displayed in the second line).
Solution

Vendor Information

KDDI
CWE (What is CWE?)

CVE (What is CVE?)

References

  1. JVN : JVN#9ADCBB12
Revision History

  • [2008/05/21]
      Web page published