Openwall GNU/*/Linux - a small security-enhanced Linux distro for servers
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Tue, 11 Feb 2014 02:05:29 -0600
From: "Joshua J. Drake" <>
Subject: Re: CVE-2014-1939 searchBoxJavaBridge_ in Android Jelly Bean

On Mon, Feb 10, 2014 at 11:32:23PM -0500, wrote:
> Use CVE-2014-1939. For example, see:
> versus:

Thanks for the CVE assignment.

For interested parties, I consider the actual issue to be the use of
the unsafe addJavascriptInterface API at all. This happens in (not in See use of the
javascriptInterfaces and mJavaScriptObjects variables and the
nativeAddJavascriptInterface JNI function.


Download attachment "signature.asc" of type "application/pgp-signature" (829 bytes)

Powered by blists - more mailing lists

Your e-mail address:

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Powered by Openwall GNU/*/Linux - Powered by OpenVZ