Upstream information

CVE-2014-3502 at MITRE

Description

Apache Cordova Android before 3.5.1 allows remote attackers to open and send data to arbitrary applications via a URL with a crafted URI scheme for an Android intent.

SUSE information

Overall state of this security issue: Does not affect SUSE products

This issue is currently rated as having moderate severity.

CVSS v2 Scores
  National Vulnerability Database
Base Score 4.3
Vector AV:N/AC:M/Au:N/C:P/I:N/A:N
Access Vector Network
Access Complexity Medium
Authentication None
Confidentiality Impact Partial
Integrity Impact None
Availability Impact None
No SUSE Bugzilla entries cross referenced.

No SUSE Security Announcements cross referenced.

List of released packages

Product(s) Fixed package version(s) References
openSUSE Tumbleweed
  • libcrypto38 >= 2.5.0-1.1
  • libcrypto38-32bit >= 2.5.0-1.1
  • libressl >= 2.5.0-1.1
  • libressl-devel >= 2.5.0-1.1
  • libressl-devel-32bit >= 2.5.0-1.1
  • libressl-devel-doc >= 2.5.0-1.1
  • libssl39 >= 2.5.0-1.1
  • libssl39-32bit >= 2.5.0-1.1
  • libtls11 >= 2.5.0-1.1
  • libtls11-32bit >= 2.5.0-1.1
Patchnames:
openSUSE Tumbleweed GA libcrypto38