Xiaomi Mi Browser Multiple Arbitrary Code Execution Vulnerabilities
BID:107578
Info
Xiaomi Mi Browser Multiple Arbitrary Code Execution Vulnerabilities
| Bugtraq ID: | 107578 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 15 2019 12:00AM |
| Updated: | Mar 15 2019 12:00AM |
| Credit: | MWR Labs - Georgi Geshev and Robert Miller |
| Vulnerable: |
Xiaomi Inc. Mi Browser 0 |
| Not Vulnerable: | |
Discussion
Xiaomi Mi Browser Multiple Arbitrary Code Execution Vulnerabilities
Xiaomi Mi Browser is prone to multiple arbitrary code-execution vulnerabilities.
Successfully exploiting these issues may allow an attacker to execute arbitrary code in the context of the current process. Failed exploits will result in denial-of-service conditions.
Xiaomi Mi Browser is prone to multiple arbitrary code-execution vulnerabilities.
Successfully exploiting these issues may allow an attacker to execute arbitrary code in the context of the current process. Failed exploits will result in denial-of-service conditions.
Solution / Fix
Xiaomi Mi Browser Multiple Arbitrary Code Execution Vulnerabilities
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
Xiaomi Mi Browser Multiple Arbitrary Code Execution Vulnerabilities
References:
References:
- Xiaomi Homepage (Xiaomi)
- (0day) (Pwn2Own) Xiaomi Mi6 Browser market.install apkPath Command Injection (Zero Day Initiative)