CVE-2018-16262 Information

Description

The pkgmgr system service in Tizen allows an unprivileged process to perform package management actions due to improper D-Bus security policy configurations. Such actions include installing decrypting and killing other packages. This affects Tizen before 5.0 M1 and Tizen-based firmwares including Samsung Galaxy Gear series before build RE2.

CVSS Vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Reference

https://media.defcon.org/DEF20CON2026/DEF20CON202620presentations/Dongsung20Kim20and20Hyoung20Kee20Choi20-20Updated/DEFCON-26-Dongsung-Kim-and-Hyoung-Kee-Choi-Your-Watch-Can-Watch-You-Updated.pdf https://review.tizen.org/git/?p=platform/core/appfw/pkgmgr-server.git;a=commit;h=aac8a95859828a058d8e06893982b11ebc81dd78 https://www.youtube.com/watch?v=3IdgBwbOT-g&feature=youtu.be

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

HIGH

Availability Impact

HIGH

Base Score

HIGH

Base Severity

8.8

Share on: