CVE-2022-43543
Summary
| CVE | CVE-2022-43543 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-12-21 09:15:00 UTC |
| Updated | 2023-01-04 18:44:00 UTC |
| Description | KDDI +Message App, NTT DOCOMO +Message App, and SoftBank +Message App contain a vulnerability caused by improper handling of Unicode control characters. +Message App displays text unprocessed, even when control characters are contained, and the text is shown based on Unicode control character's specifications. Therefore, a crafted text may display misleading web links. As a result, a spoofed URL may be displayed and phishing attacks may be conducted. Affected products and versions are as follows: KDDI +Message App for Android prior to version 3.9.2 and +Message App for iOS prior to version 3.9.4, NTT DOCOMO +Message App for Android prior to version 54.49.0500 and +Message App for iOS prior to version 3.9.4, and SoftBank +Message App for Android prior to version 12.9.5 and +Message App for iOS prior to version 3.9.4 |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Docomo | Message | All | All | All | All |
| Application | Docomo | Message | All | All | All | All |
| Application | Kddi | Message | All | All | All | All |
| Application | Kddi | Message | All | All | All | All |
| Application | Softbank | Message | All | All | All | All |
| Application | Softbank | Message | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| +メッセージ(プラスメッセージ) | スマートフォン・携帯電話 | ソフトバンク | MISC | www.softbank.jp | |
| JVN#43561812: +Message App improper handling of Unicode control characters | MISC | jvn.jp | |
| お知らせ:+メッセージ(プラスメッセージ) | サービス・機能 | au | MISC | www.au.com | |
| +メッセージ(プラスメッセージ) | サービス・機能 | NTTドコモ | MISC | www.docomo.ne.jp | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.