The Edinburgh by Bus application for Android, when Adobe PhoneGap 2.9.0 or earlier is used, allows remote attackers to execute arbitrary JavaScript code, and consequently access external-storage resources, by leveraging control over one of a number of obscure Eastern European dating sites.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Edinburgh_by_bus | Edinburghtour | - (including) | - (including) |
Cordova-ubuntu | Ubuntu | saucy | * |
Cordova-ubuntu | Ubuntu | trusty | * |
Cordova-ubuntu | Ubuntu | utopic | * |
Cordova-ubuntu | Ubuntu | vivid | * |
Cordova-ubuntu | Ubuntu | wily | * |
Cordova-ubuntu-3.4 | Ubuntu | artful | * |
Cordova-ubuntu-3.4 | Ubuntu | trusty | * |
Cordova-ubuntu-3.4 | Ubuntu | utopic | * |
Cordova-ubuntu-3.4 | Ubuntu | vivid | * |
Cordova-ubuntu-3.4 | Ubuntu | wily | * |
Cordova-ubuntu-3.4 | Ubuntu | xenial | * |
Cordova-ubuntu-3.4 | Ubuntu | yakkety | * |
Cordova-ubuntu-3.4 | Ubuntu | zesty | * |