Published:2005/04/14  Last Updated:2008/05/21

JVN#9ADCBB12
Website connection problem when a mobile phone terminal uses specific QR code

Overview

Mobile phone terminals supporting the two-dimensional code (QR code) read function are reported to have a website connection problem. When specific QR code is read, even if a user tries to connect to the URL string in the first line of the two URL lines displayed, the connection is established with the second URL.
This problem has been reported for KDDI mobile phones. The developer provides countermeasure information although they judged this problem not a vulnerability. JVN has publicized this issue in coordination with the developer to make it known to users.

Products Affected

Description

Impact

When specific QR code is read, connection could be established with an unintended site (the site displayed in the second line).

Solution

Vendor Status

Vendor Status Last Update Vendor Notes
KDDI CORPORATION Vulnerable 2005/04/14

References

JPCERT/CC Addendum

Credit

Hiromitsu Takagi reported this vulnerability to IPA.
JPCERT/CC coordinated with the vendors under Information Security Early Warning Partnership.

Other Information

JPCERT Alert
JPCERT Reports
CERT Advisory
CPNI Advisory
TRnotes
CVE
JVN iPedia JVNDB-2005-000764

Update History