High severity7.5NVD Advisory· Published Mar 22, 2018· Updated Jun 17, 2026
CVE-2018-8909
CVE-2018-8909
Description
The Wire application before 2018-03-07 for Android allows attackers to write to pathnames outside of the downloads directory via a ../ in a filename of a received file, related to AssetService.scala.
Affected products
2- Range: <2018-03-07
Patches
Vulnerability mechanics
References
1- www.x41-dsec.de/reports/X41-Kudelski-Wire-Security-Review-Android.pdfnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.