Vulnerability Description
The Google Email application 4.2.2.0200 for Android allows remote attackers to cause a denial of service (persistent application crash) via a "Content-Disposition: ;" header in an e-mail message.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| 4.2.2.0200 |
Related Weaknesses (CWE)
References
- http://hmarco.org/bugs/google_email_app_4.2.2_denial_of_service.htmlExploit
- http://openwall.com/lists/oss-security/2015/02/10/9
- http://openwall.com/lists/oss-security/2015/02/12/15
- http://packetstormsecurity.com/files/130388/Google-Email-4.4.2.0200-Denial-Of-SeExploit
- http://seclists.org/fulldisclosure/2015/Feb/58
- http://www.securityfocus.com/archive/1/534703/100/0/threaded
- http://hmarco.org/bugs/google_email_app_4.2.2_denial_of_service.htmlExploit
- http://openwall.com/lists/oss-security/2015/02/10/9
- http://openwall.com/lists/oss-security/2015/02/12/15
- http://packetstormsecurity.com/files/130388/Google-Email-4.4.2.0200-Denial-Of-SeExploit
- http://seclists.org/fulldisclosure/2015/Feb/58
- http://www.securityfocus.com/archive/1/534703/100/0/threaded
FAQ
What is CVE-2015-1574?
CVE-2015-1574 is a vulnerability with a CVSS score of 5.0 (MEDIUM). The Google Email application 4.2.2.0200 for Android allows remote attackers to cause a denial of service (persistent application crash) via a "Content-Disposition: ;" header in an e-mail message.
How severe is CVE-2015-1574?
CVE-2015-1574 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-1574?
Check the references section above for vendor advisories and patch information. Affected products include: Google Email.