SD Card Manager vulnerable to directory traversal


SD Card Manager provided by apps4u@android contains an issue in processing file names, which may result in a directory traversal (CWE-22) vulnerability.

Ryohei Koike of Sakura Information Systems Co., Ltd. reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
CVSS Severity (What is CVSS?)

CVSS V2 Severity:
Base Metrics 4.3 (Medium) [IPA Score]
  • Access Vector: Network
  • Access Complexity: Medium
  • Authentication: None
  • Confidentiality Impact: None
  • Integrity Impact: Partial
  • Availability Impact: None
Affected Products

  • SD Card Manager

All versions released prior to February 24, 2014 are affected

A remote, unauthenticated attacker may create an arbitrary file or overwrite an existing file in a directory that the application has privileges to access.

[Apply an Update]
Update the software if you are using a version that was downloaded prior to February 24, 2014.

The software version that is downloaded will differ depending on the version of Android OS that you are using.

According to the developer, SD Card Manager 2.5.6 for Android 3.2 will not have this vulnerability addressed.
Vendor Information

CWE (What is CWE?)

  1. Path Traversal(CWE-22) [IPA Evaluation]
CVE (What is CVE?)

  1. CVE-2014-1969

  1. JVN : JVN#47386847
  2. National Vulnerability Database (NVD) : CVE-2014-1969
Revision History

  • [2014/04/11]
      Web page was published
      References : Content was added