CVE-2011-0680: Medium severity android vulnerability
data/WorkingMessage.java in the Mms application in Android before 2.2.2 and 2.3.x before 2.3.2 does not properly manage the draft cache, which allows remote attackers to read SMS messages intended for other recipients in opportunistic circumstances via a standard text messaging service.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2011-0680?
CVE-2011-0680 is classified as a moderate severity vulnerability due to its potential to expose sensitive SMS message data.
How do I fix CVE-2011-0680?
To fix CVE-2011-0680, users should update their Android devices to version 2.3.2 or higher where the issue has been resolved.
What versions of Android are affected by CVE-2011-0680?
CVE-2011-0680 affects Android versions 1.5, 1.6, 2.1, and 2.2 up to 2.2.1.
What type of attack does CVE-2011-0680 enable?
CVE-2011-0680 enables remote attackers to read SMS messages that are intended for other recipients.
Is there a workaround for CVE-2011-0680 before updating?
There are no documented workarounds for CVE-2011-0680, so the best option is to update to a secure version of Android.