JVN#05924524
LINE for Windows fails to properly verify downloaded files
Overview
LINE for Windows contains a vulnerability where downloaded files are not properly verified.
Products Affected
- LINE for Windows ver 4.8.2.1125 and earlier
Description
The auto update function in LINE for Windows provided by LINE Corporation contains a vulnerability where downloaded files are not properly verified.
Impact
A successful man-in-the-middle attack may result in a specially crafted file prepared by an attacker being downloaded and executed.
Solution
Re-install the software
Re-install the software using the newest available version of the installer according to the information provided by the developer.
This vulnerability has been addressed in LINE for Windows ver 4.8.3.
Vendor Status
Vendor | Link |
LINE Corporation | [Vulnerability] The issue that LINE for Windows can not update securely |
References
JPCERT/CC Addendum
Vulnerability Analysis by JPCERT/CC
Attack Vector(AV) | Physical (P) | Local (L) | Adjacent (A) | Network (N) |
---|---|---|---|---|
Attack Complexity(AC) | High (H) | Low (L) | ||
Privileges Required(PR) | High (H) | Low (L) | None (N) | |
User Interaction(UI) | Required (R) | None (N) | ||
Scope(S) | Unchanged (U) | Changed (C) | ||
Confidentiality Impact(C) | None (N) | Low (L) | High (H) | |
Integrity Impact(I) | None (N) | Low (L) | High (H) | |
Availability Impact(A) | None (N) | Low (L) | High (H) |
Access Vector(AV) | Local (L) | Adjacent Network (A) | Network (N) |
---|---|---|---|
Access Complexity(AC) | High (H) | Medium (M) | Low (L) |
Authentication(Au) | Multiple (M) | Single (S) | None (N) |
Confidentiality Impact(C) | None (N) | Partial (P) | Complete (C) |
Integrity Impact(I) | None (N) | Partial (P) | Complete (C) |
Availability Impact(A) | None (N) | Partial (P) | Complete (C) |
Comment
This analysis assumes a man-in-the-middle attack being conducted by an attacker that places a malicious wireless LAN access point.
Credit
LINE Corporation reported this vulnerability to JPCERT/CC to notify users of its solution through JVN. JPCERT/CC and LINE Corporation coordinated under the Information Security Early Warning Partnership.
Other Information
JPCERT Alert |
|
JPCERT Reports |
|
CERT Advisory |
|
CPNI Advisory |
|
TRnotes |
|
CVE |
CVE-2016-4850 |
JVN iPedia |
JVNDB-2016-000153 |