An improper synchronization logic in Samsung Email prior to version 6.1.41.0 can leak messages in certain mailbox in plain text when STARTTLS negotiation is failed.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
The product utilizes multiple threads or processes to allow temporary access to a shared resource that can only be exclusive to one process at a time, but it does not properly synchronize these actions, which might cause simultaneous accesses of this resource by multiple threads or processes.
Link | Tags |
---|---|
https://security.samsungmobile.com/ | vendor advisory |
https://security.samsungmobile.com/serviceWeb.smsb | vendor advisory |