PT-2018-16356 · Signal · Signal Messenger For Android

CVE-2018-3988

·

Publicado

2018-12-10

·

Atualizado

2023-02-03

CVSS v3.1

4.7

Média

VetorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Signal Messenger for Android version 4.24.8
Description The issue may expose private information when using "disappearing messages." If a user uses the photo feature available in the "attach file" menu, then Signal will leave the picture in its own cache directory, which is available to any application on the system.
Recommendations For Signal Messenger for Android version 4.24.8, consider clearing the cache directory after using the photo feature in "disappearing messages" to minimize the risk of private information exposure. As a temporary workaround, restrict access to the cache directory to prevent other applications from accessing the sensitive information.

Exploit

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-3988

Produtos afetados

Signal Messenger For Android