Published:2016/08/25  Last Updated:2016/08/25

JVN#05924524
LINE for Windows fails to properly verify downloaded files

Overview

LINE for Windows contains a vulnerability where downloaded files are not properly verified.

Products Affected

  • LINE for Windows ver 4.8.2.1125 and earlier

Description

The auto update function in LINE for Windows provided by LINE Corporation contains a vulnerability where downloaded files are not properly verified.

Impact

A successful man-in-the-middle attack may result in a specially crafted file prepared by an attacker being downloaded and executed.

Solution

Re-install the software
Re-install the software using the newest available version of the installer according to the information provided by the developer.
This vulnerability has been addressed in LINE for Windows ver 4.8.3.

References

JPCERT/CC Addendum

Vulnerability Analysis by JPCERT/CC

CVSS v3 CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score: 8.1
Attack Vector(AV) Physical (P) Local (L) Adjacent (A) Network (N)
Attack Complexity(AC) High (H) Low (L)
Privileges Required(PR) High (H) Low (L) None (N)
User Interaction(UI) Required (R) None (N)
Scope(S) Unchanged (U) Changed (C)
Confidentiality Impact(C) None (N) Low (L) High (H)
Integrity Impact(I) None (N) Low (L) High (H)
Availability Impact(A) None (N) Low (L) High (H)
CVSS v2 AV:N/AC:H/Au:N/C:P/I:P/A:P
Base Score: 5.1
Access Vector(AV) Local (L) Adjacent Network (A) Network (N)
Access Complexity(AC) High (H) Medium (M) Low (L)
Authentication(Au) Multiple (M) Single (S) None (N)
Confidentiality Impact(C) None (N) Partial (P) Complete (C)
Integrity Impact(I) None (N) Partial (P) Complete (C)
Availability Impact(A) None (N) Partial (P) Complete (C)

Comment

This analysis assumes a man-in-the-middle attack being conducted by an attacker that places a malicious wireless LAN access point.

Credit

LINE Corporation reported this vulnerability to JPCERT/CC to notify users of its solution through JVN. JPCERT/CC and LINE Corporation coordinated under the Information Security Early Warning Partnership.

Other Information

JPCERT Alert
JPCERT Reports
CERT Advisory
CPNI Advisory
TRnotes
CVE CVE-2016-4850
JVN iPedia JVNDB-2016-000153