Description
The wemail_consumer_service (from the built-in application wemail) in Samsung Galaxy Gear series allows an unprivileged process to manipulate a user's mailbox, due to improper D-Bus security policy configurations. An arbitrary email can also be sent from the mailbox via the paired smartphone. This affects Tizen-based firmwares including Samsung Galaxy Gear series before build RE2.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-8123 | The wemail_consumer_service (from the built-in application wemail) in Samsung Galaxy Gear series allows an unprivileged process to manipulate a user's mailbox, due to improper D-Bus security policy configurations. An arbitrary email can also be sent from the mailbox via the paired smartphone. This affects Tizen-based firmwares including Samsung Galaxy Gear series before build RE2. |
References
History
No history.
Subscriptions
Samsung
Subscribe
Galaxy Gear
Subscribe
Galaxy Gear Firmware
Subscribe
Gear 2
Subscribe
Gear 2 Firmware
Subscribe
Gear Fit
Subscribe
Gear Fit 2
Subscribe
Gear Fit 2 Firmware
Subscribe
Gear Fit 2 Pro
Subscribe
Gear Fit 2 Pro Firmware
Subscribe
Gear Fit Firmware
Subscribe
Gear Live
Subscribe
Gear Live Firmware
Subscribe
Gear S
Subscribe
Gear S2
Subscribe
Gear S2 Firmware
Subscribe
Gear S3
Subscribe
Gear S3 Firmware
Subscribe
Gear S Firmware
Subscribe
Gear Sport
Subscribe
Gear Sport Firmware
Subscribe
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T10:17:38.462Z
Reserved: 2018-08-31T00:00:00.000Z
Link: CVE-2018-16271
No data.
Status : Modified
Published: 2020-01-22T14:15:11.277
Modified: 2024-11-21T03:52:25.797
Link: CVE-2018-16271
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD