lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [day] [month] [year] [list]
Message-ID: <54DDCEA3.3080502@upv.es>
Date: Fri, 13 Feb 2015 11:14:59 +0100
From: Hector Marco <hecmargi@....es>
To: fulldisclosure@...lists.org, bugtraq@...urityfocus.com,
  bugs@...uritytracker.com
Subject: CVE-2015-1574 - Google Email App 4.2.2 remote denial of service

Hello,


Summary:

A bug in the stock Google email application version 4.4.2.0200 has been 
found. An attacker can remotely perform an Denial Of Service attack by 
sending a specially crafted email. No interaction from the user is 
needed to produce the crash just receive the malicious email.

The CVE-2015-1574 has been assigned. Version 4.2.2.0200 running on a 
Samsung Galaxy 4 mini fully updated (19 Jan 2015) is affected. Newer 
versions 4.2.2.0400 are not affected.


Details and proof of concept exploit at:
http://hmarco.org/bugs/google_email_app_4.2.2_denial_of_service.html



Regards,
Hector Marco.
http://hmarco.org

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ