First published: Mon Jan 31 2011(Updated: )
data/WorkingMessage.java in the Mms application in Android before 2.2.2 and 2.3.x before 2.3.2 does not properly manage the draft cache, which allows remote attackers to read SMS messages intended for other recipients in opportunistic circumstances via a standard text messaging service.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Google Android | =1.6 | |
Google Android | =2.1 | |
Google Android | =2.3-rev1 | |
Google Android | =1.5 | |
Google Android | =2.2-rev1 | |
Google Android | <=2.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-0680 is classified as a moderate severity vulnerability due to its potential to expose sensitive SMS message data.
To fix CVE-2011-0680, users should update their Android devices to version 2.3.2 or higher where the issue has been resolved.
CVE-2011-0680 affects Android versions 1.5, 1.6, 2.1, and 2.2 up to 2.2.1.
CVE-2011-0680 enables remote attackers to read SMS messages that are intended for other recipients.
There are no documented workarounds for CVE-2011-0680, so the best option is to update to a secure version of Android.