CVE-2023-29751:Yandex Navigator v.6.60 for Android is vulnerable to a persistent denial of service attack through SharedPreference file manipulation.

splash
Back

Description Preview

A vulnerability in Yandex Navigator v.6.60 for Android allows unauthorized applications to cause a persistent denial of service condition by manipulating the app's SharedPreference files. When an attacker manipulates these files, it can cause the application to crash consistently upon startup, preventing normal usage of the application. This vulnerability exists due to insufficient validation of SharedPreference data, allowing malicious apps to inject invalid configurations that the Navigator app cannot properly process.

Overview

The vulnerability in Yandex Navigator v.6.60 for Android stems from improper validation of SharedPreference files, which are used to store application settings and configuration data. Unauthorized applications with the appropriate permissions can modify these files to contain invalid or malformed data. When Yandex Navigator attempts to read these manipulated SharedPreference files during startup, it crashes, resulting in a persistent denial of service condition. Users would be unable to use the navigation app until the issue is resolved, potentially causing significant inconvenience, especially for those relying on the app for navigation purposes.

Remediation

Users should update to the latest version of Yandex Navigator as soon as it becomes available with a fix for this vulnerability. In the meantime, users can try clearing the app's data and cache through the Android Settings menu (Settings > Apps > Yandex Navigator > Storage > Clear Data/Clear Cache). This will reset the application to its default state, removing any manipulated SharedPreference files. Additionally, users should be cautious about installing applications from untrusted sources that might exploit this vulnerability. App developers should implement proper validation of SharedPreference data and consider using more secure storage options for sensitive configuration data.

References

  1. GitHub repository with detailed information: https://github.com/LianKee/SO-CVEs/blob/main/CVEs/CVE-2023-29751/CVE%20detailed.md
  2. CVE-2023-29751 in the National Vulnerability Database
  3. Yandex Navigator official website for potential security updates

Industry ExposureMost to least
This section illustrates the prevalence of a specific Common Vulnerabilities and Exposures (CVE) across various industries based on customer reports. The ranking displays industries from the most to least affected by this particular vulnerability, offering valuable insight into where this CVE has been most frequently observed. This information can help organizations within these sectors prioritize their security efforts, understand their relative risk exposure compared to their peers, and focus remediation strategies where they are most needed. By understanding the industry-specific impact, organizations can make more informed decisions regarding patching, resource allocation, and overall risk management related to this CVE.

  1. Accommodation & Food Services
    Accommodation & Food Services
  2. Administrative, Support, Waste Management & Remediation Services
    Administrative, Support, Waste Management & Remediation Services
  3. Agriculture, Forestry Fishing & Hunting
    Agriculture, Forestry Fishing & Hunting
  4. Arts, Entertainment & Recreation
    Arts, Entertainment & Recreation
  5. Construction
    Construction
  6. Educational Services
    Educational Services
  7. Finance and Insurance
    Finance and Insurance
  8. Health Care & Social Assistance
    Health Care & Social Assistance
  9. Information
    Information
  10. Management of Companies & Enterprises
    Management of Companies & Enterprises
  11. Manufacturing
    Manufacturing
  12. Mining
    Mining
  13. Other Services (except Public Administration)
    Other Services (except Public Administration)
  14. Professional, Scientific, & Technical Services
    Professional, Scientific, & Technical Services
  15. Public Administration
    Public Administration
  16. Real Estate Rental & Leasing
    Real Estate Rental & Leasing
  17. Retail Trade
    Retail Trade
  18. Transportation & Warehousing
    Transportation & Warehousing
  19. Utilities
    Utilities
  20. Wholesale Trade
    Wholesale Trade

Focus on What Matters

  1. See Everything.
  2. Identify True Risk.
  3. Proactively Mitigate Threats.

Let's talk!

background