MTP service exposed during emergency dialer
CVE-2015-7946

7.3HIGH

Key Information:

Vendor
Canonical
Vendor
CVE Published:
7 May 2020

Summary

Information Exposure vulnerability in Unity8 as used on the Ubuntu phone and possibly also in Unity8 shipped elsewhere. This allows an attacker to enable the MTP service by opening the emergency dialer. Fixed in 8.11+16.04.20160111.1-0ubuntu1 and 8.11+15.04.20160122-0ubuntu1.

Affected Version(s)

unity8 (Ubuntu) 8.11 < 8.11+16.04.20160111.1-0ubuntu1

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Michael Terry
.