{ "id": "CVE-2011-0680", "sourceIdentifier": "cve@mitre.org", "published": "2011-01-31T20:00:51.547", "lastModified": "2017-08-17T01:33:41.323", "vulnStatus": "Modified", "descriptions": [ { "lang": "en", "value": "data/WorkingMessage.java in the Mms application in Android before 2.2.2 and 2.3.x before 2.3.2 does not properly manage the draft cache, which allows remote attackers to read SMS messages intended for other recipients in opportunistic circumstances via a standard text messaging service." }, { "lang": "es", "value": "data/WorkingMessage.java en la aplicaci\u00f3n Mms en Android anterior a v2.2.2 y v2.3.x anterior a v2.3.2 no maneja adecuadamente la 'draft' cach\u00e9, lo que permite a atacantes remotos leer mensajes SMS previstos para otros destinatarios en circustancias oportunas a trav\u00e9s de un servicio est\u00e1ndar de mensajes de texto." } ], "metrics": { "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N", "accessVector": "NETWORK", "accessComplexity": "LOW", "authentication": "NONE", "confidentialityImpact": "PARTIAL", "integrityImpact": "NONE", "availabilityImpact": "NONE", "baseScore": 5.0 }, "baseSeverity": "MEDIUM", "exploitabilityScore": 10.0, "impactScore": 2.9, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "NVD-CWE-Other" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:o:google:android:*:*:*:*:*:*:*:*", "versionEndIncluding": "2.2.1", "matchCriteriaId": "0E6C3F8E-2B91-425F-8134-CEB2BEE12EFA" }, { "vulnerable": true, "criteria": "cpe:2.3:o:google:android:1.5:*:*:*:*:*:*:*", "matchCriteriaId": "8C354829-6BEB-4C67-972A-60367073753C" }, { "vulnerable": true, "criteria": "cpe:2.3:o:google:android:1.6:*:*:*:*:*:*:*", "matchCriteriaId": "702B40EB-76BC-4686-A46E-D02DBE3A86E7" }, { "vulnerable": true, "criteria": "cpe:2.3:o:google:android:2.1:*:*:*:*:*:*:*", "matchCriteriaId": "A33DBF65-09A6-4149-BABE-2FFFBF10C31D" }, { "vulnerable": true, "criteria": "cpe:2.3:o:google:android:2.2:rev1:*:*:*:*:*:*", "matchCriteriaId": "D1755B91-1B6B-4A9E-BB6B-22B399A6DD02" }, { "vulnerable": true, "criteria": "cpe:2.3:o:google:android:2.3:rev1:*:*:*:*:*:*", "matchCriteriaId": "61D64B87-F1F1-4E52-86AE-F28E2C43A9A8" } ] } ] } ], "references": [ { "url": "http://android.git.kernel.org/?p=platform/packages/apps/Mms.git;a=commit;h=18d6b7e9d2e538fb3c0264332b96c02abf367267", "source": "cve@mitre.org", "tags": [ "Patch" ] }, { "url": "http://android.git.kernel.org/?p=platform/packages/apps/Mms.git;a=commit;h=4d26623ce82230e8e7009adb921c5edea370a9e0", "source": "cve@mitre.org", "tags": [ "Patch" ] }, { "url": "http://code.google.com/p/android/issues/detail?id=9392#c1460", "source": "cve@mitre.org" }, { "url": "http://code.google.com/p/android/issues/detail?id=9392#c1620", "source": "cve@mitre.org" }, { "url": "http://phandroid.com/2011/01/21/android-2-3-2-update-pushing-to-nexus-s-phone-fixes-sms-bug/", "source": "cve@mitre.org" }, { "url": "http://twitter.com/GalaxySsupport/statuses/28078194607263744", "source": "cve@mitre.org" }, { "url": "http://www.engadget.com/2011/01/22/nexus-one-gets-tiny-update-to-android-2-2-2-probably-fixes-sms/", "source": "cve@mitre.org" }, { "url": "http://www.htcphones.net/nexus-one-update-to-android-2-2-2/", "source": "cve@mitre.org" }, { "url": "http://www.samsunghub.com/2011/01/22/nexus-s-gets-android-2-3-2-fixes-sms-bug/", "source": "cve@mitre.org" }, { "url": "http://www.securityfocus.com/bid/46105", "source": "cve@mitre.org" }, { "url": "http://www.theinquirer.net/inquirer/news/1939386/google-updates-nexus-android-222", "source": "cve@mitre.org", "tags": [ "Patch" ] }, { "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/65125", "source": "cve@mitre.org" } ] }