CVE Vulnerabilities

CVE-2014-1881

Published: Mar 03, 2014 | Modified: Mar 03, 2014
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Apache Cordova 3.3.0 and earlier and Adobe PhoneGap 2.9.0 and earlier allow remote attackers to bypass intended device-resource restrictions of an event-based bridge via a crafted library clone that leverages IFRAME script execution and waits a certain amount of time for an OnJsPrompt handler return value as an alternative to correct synchronization.

Affected Software

Name Vendor Start Version End Version
Cordova Apache 3.0.0 3.0.0
Cordova Apache 3.0.0 3.0.0
Cordova Apache 3.1.0 3.1.0
Cordova Apache 3.1.0 3.1.0
Cordova Apache 3.2.0 3.2.0
Cordova Apache 3.2.0 3.2.0
Cordova Apache * 3.3.0
Cordova Apache 3.3.0 3.3.0
Cordova-ubuntu Ubuntu saucy *
Cordova-ubuntu Ubuntu trusty *
Cordova-ubuntu Ubuntu utopic *
Cordova-ubuntu Ubuntu vivid *
Cordova-ubuntu Ubuntu wily *
Cordova-ubuntu-3.4 Ubuntu artful *
Cordova-ubuntu-3.4 Ubuntu trusty *
Cordova-ubuntu-3.4 Ubuntu utopic *
Cordova-ubuntu-3.4 Ubuntu vivid *
Cordova-ubuntu-3.4 Ubuntu wily *
Cordova-ubuntu-3.4 Ubuntu xenial *
Cordova-ubuntu-3.4 Ubuntu yakkety *
Cordova-ubuntu-3.4 Ubuntu zesty *

References