app-updates.agilebits.comConfirmation
https://app-updates.agilebits.com/product_history/OPA4 CVE-2018-13042
MEDIUM
1Password < 7.0 - Denial of Service
Record summary
CVE-2018-13042 has a selected CVSS score of 5.9 (medium); EIP currently links 1 catalogued exploit.
Description
The 1Password application 6.8 for Android is affected by a Denial Of Service vulnerability. By starting the activity com.agilebits.onepassword.filling.openyolo.OpenYoloDeleteActivity or com.agilebits.onepassword.filling.openyolo.OpenYoloRetrieveActivity from an external application (since they are exported), it is possible to crash the 1Password instance.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDB1Password < 7.0 - Denial of ServiceExploitDB exploitby Valerio BrussaniNot analyzed1 file
References
4nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-13042 46165exploit
https://www.exploit-db.com/exploits/46165 valbrux.it
https://www.valbrux.it/blog/2019/01/22/cve-2018-13042-1password-android-7-0-denial-of-service