CVE-2014-1423
Publication date 7 May 2020
Last updated 25 August 2025
Ubuntu priority
Cvss 3 Severity Score
Description
signond before 8.57+15.04.20141127.1-0ubuntu1, as used in Ubuntu Touch, did not properly restrict applications from querying oath tokens due to incorrect checks and the missing installation of the signon-apparmor-extension. An attacker could use this create a malicious click app that collects oauth tokens for other applications, exposing sensitive information.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| signon | ||
| 18.04 LTS bionic |
Fixed 8.57+15.04.20141127.1-0ubuntu1
|
|
| 16.04 LTS xenial |
Fixed 8.57+15.04.20141127.1-0ubuntu1
|
|
| 14.04 LTS trusty | Not in release | |
Notes
mdeslaur
This is fixed in vivid. Setting to low priority for trusty and utopic since it is specific to click apps.
Patch details
| Package | Patch details |
|---|---|
| signon |
|
Severity score breakdown
CVSS version: CVSS v3.0
Base score
5.5 · Medium
Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N