製品・ソフトウェアに関する情報
MTK チップセットを使用する LG デバイスのにおける任意のサードパーティアプリケーションにアクセスされる脆弱性
Title MTK チップセットを使用する LG デバイスのにおける任意のサードパーティアプリケーションにアクセスされる脆弱性
Summary

MTK チップセットを使用する LG デバイスには、任意のサードパーティアプリケーションにアクセスされる脆弱性が存在します。 ベンダは、本脆弱性を LVE-SMP-160019 として公開しています。

Possible impacts android.content.Intent の通信オブジェクトを介して、任意のサードパーティアプリケーションにアクセスされる可能性があります。
Solution

ベンダ情報および参考情報を参照して適切な対策を実施してください。

Publication Date Nov. 17, 2016, midnight
Registration Date Jan. 30, 2017, 10:46 a.m.
Last Update Jan. 30, 2017, 10:46 a.m.
CVSS3.0 : 警告
Score 5.5
Vector CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
CVSS2.0 : 警告
Score 4.3
Vector AV:N/AC:M/Au:N/C:P/I:N/A:N
Affected System
LG Electronics
LG Mobile 
CVE (情報セキュリティ 共通脆弱性識別子)
CWE (共通脆弱性タイプ一覧)
ベンダー情報
Change Log
No Changed Details Date of change
0 [2017年01月30日]
  掲載
Feb. 17, 2018, 10:37 a.m.

NVD Vulnerability Information
CVE-2016-10135
Summary

An issue was discovered on LG devices using the MTK chipset with L(5.0/5.1), M(6.0/6.0.1), and N(7.0) software, and RCA Voyager Tablet, BLU Advance 5.0, and BLU R1 HD devices. The MTKLogger app with a package name of com.mediatek.mtklogger has application components that are accessible to any application that resides on the device. Namely, the com.mediatek.mtklogger.framework.LogReceiver and com.mediatek.mtklogger.framework.MTKLoggerService application components are exported since they contain an intent filter, are not protected by a custom permission, and do not explicitly set the android:exported attribute to false. Therefore, these components are exported by default and are thus accessible to any third party application by using android.content.Intent object for communication. These application components can be used to start and stop the logs using Intent objects with embedded data. The available logs are the GPS log, modem log, network log, and mobile log. The base directory that contains the directories for the 4 types of logs is /sdcard/mtklog which makes them accessible to apps that require the READ_EXTERNAL_STORAGE permission. The GPS log contains the GPS coordinates of the user as well as a timestamp for the coordinates. The modem log contains AT commands and their parameters which allow the user's outgoing and incoming calls and text messages to be obtained. The network log is a tcpdump network capture. The mobile log contains the Android log, which is not available to third-party apps as of Android 4.1. The LG ID is LVE-SMP-160019.

Publication Date Jan. 13, 2017, 6:59 p.m.
Registration Date Jan. 26, 2021, 2:05 p.m.
Last Update Nov. 21, 2024, 11:43 a.m.
Affected software configurations
Configuration1 or higher or less more than less than
cpe:2.3:o:lg:lg_mobile:6.0:*:*:*:*:*:*:*
cpe:2.3:o:lg:lg_mobile:6.0.1:*:*:*:*:*:*:*
cpe:2.3:o:lg:lg_mobile:7.0:*:*:*:*:*:*:*
cpe:2.3:o:lg:lg_mobile:5.0:*:*:*:*:*:*:*
cpe:2.3:o:lg:lg_mobile:5.1:*:*:*:*:*:*:*
Related information, measures and tools
Common Vulnerabilities List