[Q] Is a fix available?

Search This thread

winlinand

Senior Member
Nov 27, 2013
84
10
Security vulnerabilities were detected on this device.

Verizon Sm-n900v (Samsung)
Android 4.3 Build JSS15J.N900VVRUBMJE
English/United States (en_US)

Security Advisor v1.0.21
Last scan: Mar 15, 2014 10:15:23 PM
Vulnerable software: 1
Total Vulnerabilities: 1

Vulnerable Software

Android OS / version 4.3 / com.google.android
Vulnerabilities: 1
Severity: 1 High

1) Severity 8.8, CVE-2013-6271

Android 4.0 through 4.3 allows attackers to bypass intended access restrictions and remove device locks via a crafted application that invokes the updateUnlockMethodAndFinish method in the com.android.settings.ChooseLockGeneric class with the PASSWORD_QUALITY_UNSPECIFIED option.
 

winlinand

Senior Member
Nov 27, 2013
84
10

Attachments

  • uploadfromtaptalk1394964747779.jpg
    uploadfromtaptalk1394964747779.jpg
    49.6 KB · Views: 91

johnciaccio

Senior Member
Aug 20, 2010
560
120
As it states all devices with Android 4.0 through 4.3 are effected. The update would be Android 4.4 Kitkat.

If I read it right it is stating that a program could be written that changes your lock screen. This could allow someone via a program that you install change it from one where you may have a pin or some other secure input to just swiping or disabling the lock screen all together.

I would not worry to much as long as you install apps only from the play store and actually read what it has access to.