CVE-2020-9759

A Vulnerability of LG Electronic web OS TV Emulator could allow an attacker to escalate privileges and overwrite certain files. This vulnerability is due to wrong environment setting. An attacker could exploit this vulnerability through crafted configuration files and executable files.
References
Link Resource
https://blog.recurity-labs.com/2021-02-03/webOS_Pt1.html Exploit Third Party Advisory
https://lists.debian.org/debian-lts-announce/2021/09/msg00018.html Mailing List Not Applicable Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:o:lg:webos:-:*:*:*:*:*:*:*

History

22 Apr 2022, 19:05

Type Values Removed Values Added
References (MLIST) https://lists.debian.org/debian-lts-announce/2021/09/msg00018.html - (MLIST) https://lists.debian.org/debian-lts-announce/2021/09/msg00018.html - Mailing List, Not Applicable, Third Party Advisory
References (CONFIRM) https://blog.recurity-labs.com/2021-02-03/webOS_Pt1.html - (CONFIRM) https://blog.recurity-labs.com/2021-02-03/webOS_Pt1.html - Exploit, Third Party Advisory
CPE cpe:2.3:a:weechat:weechat:*:*:*:*:*:*:*:* cpe:2.3:o:lg:webos:-:*:*:*:*:*:*:*
CVSS v2 : 5.0
v3 : 7.5
v2 : 9.3
v3 : 7.8
CWE CWE-476 CWE-494

30 Sep 2021, 14:15

Type Values Removed Values Added
References
  • (MLIST) https://lists.debian.org/debian-lts-announce/2021/09/msg00018.html -

Information

Published : 2020-03-23 16:15

Updated : 2024-02-04 21:00


NVD link : CVE-2020-9759

Mitre link : CVE-2020-9759

CVE.ORG link : CVE-2020-9759


JSON object : View

Products Affected

lg

  • webos
CWE
CWE-494

Download of Code Without Integrity Check