[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250770

 
 

909

 
 

196157

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2011-0680Date: (C)2011-01-31   (M)2023-12-22


data/WorkingMessage.java in the Mms application in Android before 2.2.2 and 2.3.x before 2.3.2 does not properly manage the draft cache, which allows remote attackers to read SMS messages intended for other recipients in opportunistic circumstances via a standard text messaging service.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 5.0
Exploit Score: 10.0
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: PARTIAL
Integrity: NONE
Availability: NONE
  
Reference:
BID-46105
android-workingmessage-info-disclosure(65125)
http://android.git.kernel.org/?p=platform/packages/apps/Mms.git%3Ba=commit%3Bh=18d6b7e9d2e538fb3c0264332b96c02abf367267
http://android.git.kernel.org/?p=platform/packages/apps/Mms.git%3Ba=commit%3Bh=4d26623ce82230e8e7009adb921c5edea370a9e0
http://code.google.com/p/android/issues/detail?id=9392#c1460
http://code.google.com/p/android/issues/detail?id=9392#c1620
http://phandroid.com/2011/01/21/android-2-3-2-update-pushing-to-nexus-s-phone-fixes-sms-bug/
http://twitter.com/GalaxySsupport/statuses/28078194607263744
http://www.engadget.com/2011/01/22/nexus-one-gets-tiny-update-to-android-2-2-2-probably-fixes-sms/
http://www.htcphones.net/nexus-one-update-to-android-2-2-2/
http://www.samsunghub.com/2011/01/22/nexus-s-gets-android-2-3-2-fixes-sms-bug/
http://www.theinquirer.net/inquirer/news/1939386/google-updates-nexus-android-222

CPE    6
cpe:/o:google:android:2.3:rev1
cpe:/o:google:android
cpe:/o:google:android:2.2:rev1
cpe:/o:google:android:2.1
...
OVAL    1
oval:org.secpod.oval:def:6505

© SecPod Technologies