usnistgov / mobile-threat-catalogue

NIST/NCCoE Mobile Threat Catalogue
https://pages.nist.gov/mobile-threat-catalogue
Other
142 stars 40 forks source link

Adding CVE's for MTC Category: Arbitrary code execution via a maliciously crafted file (e.g. graphic, audio, font, x509 certificate) #227

Closed cjones1 closed 7 years ago

cjones1 commented 7 years ago

General Comment

Threat ID: If the comment is specific to a given threat, provide the ID for that threat. Otherwise, leave this blank.

Type of Comment: T Enter the letter that best describes the nature of your comment

Proposed Change: Adding CVE's for given MTC Category. With as much detail as possible, what change should be made.

Justification: Need CVE's to be used as examples for this threat in the MTC. Provide reasoning as to why the proposed change is necessary. For technical comments, providing references to supporting sources is encouraged.