Skype for Android stores sensitive user data without encryption in sqlite3 databases that have weak permissions, which allows local applications to read user IDs, contacts, phone numbers, date of birth, instant message logs, and other private information.
References
Configurations
History
21 Nov 2024, 01:26
Type | Values Removed | Values Added |
---|---|---|
References | () http://blogs.skype.com/security/2011/04/privacy_vulnerability_in_skype.html - | |
References | () http://www.androidpolice.com/2011/04/14/exclusive-vulnerability-in-skype-for-android-is-exposing-your-name-phone-number-chat-logs-and-a-lot-more/ - Exploit | |
References | () http://www.securitytracker.com/id?1025387 - | |
References | () http://www.theregister.co.uk/2011/04/15/skype_for_android_vulnerable/ - |
Information
Published : 2011-04-18 18:55
Updated : 2024-11-21 01:26
NVD link : CVE-2011-1717
Mitre link : CVE-2011-1717
CVE.ORG link : CVE-2011-1717
JSON object : View
Products Affected
skype
- skype_for_android
CWE
CWE-264
Permissions, Privileges, and Access Controls