OpenSSLX509CertificateChecker 1.0.12 [免費版]

軟體介紹

This app verifies if your device is still vulnerable to CVE-2015-3825 / CVE-2015-3837 aka "One Class to Rule Them All", by checking if it contains the vulnerable conscrypt's OpenSSLX509Certificate class. A patch was released in August 2015 by Google. CVE-2015-3825 / CVE-2015-3837 is a code execution vulnerability discovered by Or Peles & Roee Hay, which allows for malware to takeover your device. It's due to a deserialization vulnerability in the OpenSSLX509Certificate class. The vulnerability was first published in USENIX WOOT '15: https://www.usenix.org/conference/woot15/workshop-program/presentation/peles. A video demo of successful exploitation of this vulnerability is available here: https://www.youtube.com/watch?v=VekzwVdwqIY It will also be presented in RSA Conference 2016: https://www.rsaconference.com/events/us16/agenda/sessions/2455/android-serialization-vulnerabilities-revisited

歷史版本

Free Download 二維碼下載
  • 軟體名稱: OpenSSLX509CertificateChecker
  • 軟體分類: 工具
  • APK名稱: roeeh.conscryptchecker
  • 最新版本: 1.0.12
  • 支持ROM: 2.3及更高版本
  • 軟體大小 : 1.74 MB
  • 更新日期: 2022-09-28