English
The Internet threat alert status is currently normal. At present, no major epidemics or other serious incidents have been recorded by Kaspersky Lab’s monitoring service. Internet threat level: 1

Sleipnir Mobile for Android Arbitrary Java Method Execution Vulnerability


Secunia ID

SA50094

CVE-ID

CVE-2012-2649, CVE-2012-4004

Release Date

08 Aug 2012

Criticality

Highly Critical

Solution Status

Vendor Patch

Software

Sleipnir Mobile for Android 2.x

Where

From remote

Impact
System access

This covers vulnerabilities where malicious people are able to gain system access and execute arbitrary code with the privileges of a local user.

Description

A vulnerability has been reported in Sleipnir Mobile for Android, which can be exploited by malicious people to compromise a user's device.

The vulnerability is caused due to an error when handling certain web pages and can be exploited to execute an arbitrary Java method.

Successful exploitation allows execution of arbitrary code via a specially crafted web page.

The vulnerability is reported in Sleipnir Mobile for Android and Sleipnir Mobile Black Edition for Android versions 2.2.0 and prior.

Solution

Update to version 2.2.2.

Reported by

JVN credits Gaku Mochizuki, Mitsui Bussan Secure Directions, Inc.

Original Advisory

Sleipnir:
https://play.google.com/store/apps/details?id=jp.co.fenrir.android.sleipnir

JVN:
http://jvn.jp/en/jp/JVN99730704/index.html
http://jvndb.jvn.jp/en/contents/2012/JVNDB-2012-000076.html