The COVIDSafe (Australia) app 1.0 and 1.1 for iOS allows a remote attacker to crash the app, and consequently interfere with COVID-19 contact tracing, via a Bluetooth advertisement containing manufacturer data that is too short. This occurs because of an erroneous OpenTrace manuData.subdata call. The ABTraceTogether (Alberta), ProteGO (Poland), and TraceTogether (Singapore) apps were also affected.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2020-05-14T04:36:11
Updated: 2024-08-04T12:04:22.554Z
Reserved: 2020-05-07T00:00:00
Link: CVE-2020-12717
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-05-14T05:15:10.987
Modified: 2024-11-21T05:00:08.237
Link: CVE-2020-12717
Redhat
No data.