CVE-2011-0680
CVE-2011-0680
data/WorkingMessage.java in the Mms application in Android before 2.2.2 and 2.3.x before 2.3.2 does not properly manage the draft cache, which allows remote attackers to read SMS messages intended for other recipients in opportunistic circumstances via a standard text messaging service.
Productos afectados
n/a · n/a¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →Referencias
http://android.git.kernel.org/?p=platform/packages/apps/Mms.git%3Ba=commit%3Bh=18d6b7e9d2e538fb3c0264332b96c02abf367267http://android.git.kernel.org/?p=platform/packages/apps/Mms.git%3Ba=commit%3Bh=4d26623ce82230e8e7009adb921c5edea370a9e0http://code.google.com/p/android/issues/detail?id=9392#c1460http://code.google.com/p/android/issues/detail?id=9392#c1620http://phandroid.com/2011/01/21/android-2-3-2-update-pushing-to-nexus-s-phone-fixes-sms-bug/https://exchange.xforce.ibmcloud.com/vulnerabilities/65125http://twitter.com/GalaxySsupport/statuses/28078194607263744http://www.engadget.com/2011/01/22/nexus-one-gets-tiny-update-to-android-2-2-2-probably-fixes-sms/http://www.htcphones.net/nexus-one-update-to-android-2-2-2/http://www.samsunghub.com/2011/01/22/nexus-s-gets-android-2-3-2-fixes-sms-bug/http://www.securityfocus.com/bid/46105http://www.theinquirer.net/inquirer/news/1939386/google-updates-nexus-android-222