CVE-2011-0680

data/WorkingMessage.java in the Mms application in Android before 2.2.2 and 2.3.x before 2.3.2 does not properly manage the draft cache, which allows remote attackers to read SMS messages intended for other recipients in opportunistic circumstances via a standard text messaging service.
References
Link Resource
http://android.git.kernel.org/?p=platform/packages/apps/Mms.git%3Ba=commit%3Bh=18d6b7e9d2e538fb3c0264332b96c02abf367267
http://android.git.kernel.org/?p=platform/packages/apps/Mms.git%3Ba=commit%3Bh=4d26623ce82230e8e7009adb921c5edea370a9e0
http://code.google.com/p/android/issues/detail?id=9392#c1460
http://code.google.com/p/android/issues/detail?id=9392#c1620
http://phandroid.com/2011/01/21/android-2-3-2-update-pushing-to-nexus-s-phone-fixes-sms-bug/
http://twitter.com/GalaxySsupport/statuses/28078194607263744
http://www.engadget.com/2011/01/22/nexus-one-gets-tiny-update-to-android-2-2-2-probably-fixes-sms/
http://www.htcphones.net/nexus-one-update-to-android-2-2-2/
http://www.samsunghub.com/2011/01/22/nexus-s-gets-android-2-3-2-fixes-sms-bug/
http://www.securityfocus.com/bid/46105
http://www.theinquirer.net/inquirer/news/1939386/google-updates-nexus-android-222 Patch
https://exchange.xforce.ibmcloud.com/vulnerabilities/65125
http://android.git.kernel.org/?p=platform/packages/apps/Mms.git%3Ba=commit%3Bh=18d6b7e9d2e538fb3c0264332b96c02abf367267
http://android.git.kernel.org/?p=platform/packages/apps/Mms.git%3Ba=commit%3Bh=4d26623ce82230e8e7009adb921c5edea370a9e0
http://code.google.com/p/android/issues/detail?id=9392#c1460
http://code.google.com/p/android/issues/detail?id=9392#c1620
http://phandroid.com/2011/01/21/android-2-3-2-update-pushing-to-nexus-s-phone-fixes-sms-bug/
http://twitter.com/GalaxySsupport/statuses/28078194607263744
http://www.engadget.com/2011/01/22/nexus-one-gets-tiny-update-to-android-2-2-2-probably-fixes-sms/
http://www.htcphones.net/nexus-one-update-to-android-2-2-2/
http://www.samsunghub.com/2011/01/22/nexus-s-gets-android-2-3-2-fixes-sms-bug/
http://www.securityfocus.com/bid/46105
http://www.theinquirer.net/inquirer/news/1939386/google-updates-nexus-android-222 Patch
https://exchange.xforce.ibmcloud.com/vulnerabilities/65125
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:google:android:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:1.5:*:*:*:*:*:*:*
cpe:2.3:o:google:android:1.6:*:*:*:*:*:*:*
cpe:2.3:o:google:android:2.1:*:*:*:*:*:*:*
cpe:2.3:o:google:android:2.2:rev1:*:*:*:*:*:*
cpe:2.3:o:google:android:2.3:rev1:*:*:*:*:*:*

History

21 Nov 2024, 01:24

Type Values Removed Values Added
References () http://android.git.kernel.org/?p=platform/packages/apps/Mms.git%3Ba=commit%3Bh=18d6b7e9d2e538fb3c0264332b96c02abf367267 - () http://android.git.kernel.org/?p=platform/packages/apps/Mms.git%3Ba=commit%3Bh=18d6b7e9d2e538fb3c0264332b96c02abf367267 -
References () http://android.git.kernel.org/?p=platform/packages/apps/Mms.git%3Ba=commit%3Bh=4d26623ce82230e8e7009adb921c5edea370a9e0 - () http://android.git.kernel.org/?p=platform/packages/apps/Mms.git%3Ba=commit%3Bh=4d26623ce82230e8e7009adb921c5edea370a9e0 -
References () http://code.google.com/p/android/issues/detail?id=9392#c1460 - () http://code.google.com/p/android/issues/detail?id=9392#c1460 -
References () http://code.google.com/p/android/issues/detail?id=9392#c1620 - () http://code.google.com/p/android/issues/detail?id=9392#c1620 -
References () http://phandroid.com/2011/01/21/android-2-3-2-update-pushing-to-nexus-s-phone-fixes-sms-bug/ - () http://phandroid.com/2011/01/21/android-2-3-2-update-pushing-to-nexus-s-phone-fixes-sms-bug/ -
References () http://twitter.com/GalaxySsupport/statuses/28078194607263744 - () http://twitter.com/GalaxySsupport/statuses/28078194607263744 -
References () http://www.engadget.com/2011/01/22/nexus-one-gets-tiny-update-to-android-2-2-2-probably-fixes-sms/ - () http://www.engadget.com/2011/01/22/nexus-one-gets-tiny-update-to-android-2-2-2-probably-fixes-sms/ -
References () http://www.htcphones.net/nexus-one-update-to-android-2-2-2/ - () http://www.htcphones.net/nexus-one-update-to-android-2-2-2/ -
References () http://www.samsunghub.com/2011/01/22/nexus-s-gets-android-2-3-2-fixes-sms-bug/ - () http://www.samsunghub.com/2011/01/22/nexus-s-gets-android-2-3-2-fixes-sms-bug/ -
References () http://www.securityfocus.com/bid/46105 - () http://www.securityfocus.com/bid/46105 -
References () http://www.theinquirer.net/inquirer/news/1939386/google-updates-nexus-android-222 - Patch () http://www.theinquirer.net/inquirer/news/1939386/google-updates-nexus-android-222 - Patch
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/65125 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/65125 -

07 Nov 2023, 02:06

Type Values Removed Values Added
References
  • {'url': 'http://android.git.kernel.org/?p=platform/packages/apps/Mms.git;a=commit;h=18d6b7e9d2e538fb3c0264332b96c02abf367267', 'name': 'http://android.git.kernel.org/?p=platform/packages/apps/Mms.git;a=commit;h=18d6b7e9d2e538fb3c0264332b96c02abf367267', 'tags': ['Patch'], 'refsource': 'CONFIRM'}
  • {'url': 'http://android.git.kernel.org/?p=platform/packages/apps/Mms.git;a=commit;h=4d26623ce82230e8e7009adb921c5edea370a9e0', 'name': 'http://android.git.kernel.org/?p=platform/packages/apps/Mms.git;a=commit;h=4d26623ce82230e8e7009adb921c5edea370a9e0', 'tags': ['Patch'], 'refsource': 'MISC'}
  • () http://android.git.kernel.org/?p=platform/packages/apps/Mms.git%3Ba=commit%3Bh=18d6b7e9d2e538fb3c0264332b96c02abf367267 -
  • () http://android.git.kernel.org/?p=platform/packages/apps/Mms.git%3Ba=commit%3Bh=4d26623ce82230e8e7009adb921c5edea370a9e0 -

Information

Published : 2011-01-31 20:00

Updated : 2024-11-21 01:24


NVD link : CVE-2011-0680

Mitre link : CVE-2011-0680

CVE.ORG link : CVE-2011-0680


JSON object : View

Products Affected

google

  • android