CVE-2018-16267 Information

Description

The system-popup system service in Tizen allows an unprivileged process to perform popup-related system actions due to improper D-Bus security policy configurations. Such actions include the triggering system poweroff menu and prompting a popup with arbitrary strings. This affects Tizen before 5.0 M1 and Tizen-based firmwares including Samsung Galaxy Gear series before build RE2.

CVSS Vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

Reference

https://media.defcon.org/DEF20CON2026/DEF20CON202620presentations/Dongsung20Kim20and20Hyoung20Kee20Choi20-20Updated/DEFCON-26-Dongsung-Kim-and-Hyoung-Kee-Choi-Your-Watch-Can-Watch-You-Updated.pdf https://review.tizen.org/git/?p=platform/core/system/system-popup.git;a=commit;h=57b3c2f3cd61c6f432e7abe3a2d8b0df72fd4b0e https://www.youtube.com/watch?v=3IdgBwbOT-g&feature=youtu.be

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

NONE

Availability Impact

HIGH

Base Score

HIGH

Base Severity

8.1

Share on: