Content Hub before version 0.0+15.04.20150331-0ubuntu1.0 DBUS API only requires a file path for a content item, it doesnt actually require the confined app have access to the file to create a transfer. This could allow a malicious application using the DBUS API to export file:///etc/passwd which would then send a copy of that file to another app.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ubuntu_linux | Canonical | 15.04 (including) | 15.04 (including) |
Content-hub | Ubuntu | vivid | * |
Content-hub | Ubuntu | vivid/stable-phone-overlay | * |
Content-hub | Ubuntu | wily | * |