기술
This app verifies if your device is still vulnerable to CVE-2015-3825 / CVE-2015-3837 aka "One Class to Rule Them All", by checking if it contains the vulnerable
conscrypt's OpenSSLX509Certificate class. A patch was released in August 2015 by Google.
CVE-2015-3825 / CVE-2015-3837 is a code execution vulnerability discovered by Or Peles & Roee Hay, which allows for malware to takeover your device. It's due to a
deserialization vulnerability in the OpenSSLX509Certificate class. The vulnerability was first published in USENIX WOOT '15:
https://www.usenix.org/conference/woot15/workshop-program/presentation/peles.
A video demo of successful exploitation of this vulnerability is available here:
https://www.youtube.com/watch?v=VekzwVdwqIY
It will also be presented in RSA Conference 2016: https://www.rsaconference.com/events/us16/agenda/sessions/2455/android-serialization-vulnerabilities-revisited
이전 버전
Free Download
QR 코드에 의해 다운로드
- 앱 이름: OpenSSLX509CertificateChecker
- 종류: 도구
- 앱코드: roeeh.conscryptchecker
- 버전: 1.0.12
- 요구 사항: 2.3이상
- 파일 크기 : 1.74 MB
- 업데이트: 2022-09-28