CVE-2011-1001: Input Validation
dexdump in Android SDK before 2.3 does not properly perform structural verification, which allows user-assisted remote attackers to cause a denial of service (dexdump crash) and possibly execute arbitrary code via a malformed APK or dex file that calls a method using more arguments than the number of register that have been declared for that method.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2011-1001?
CVE-2011-1001 has been classified as a medium severity vulnerability.
How do I fix CVE-2011-1001?
To fix CVE-2011-1001, upgrade to a version of the Android SDK later than 2.3.
What does CVE-2011-1001 affect?
CVE-2011-1001 affects versions of the Android SDK prior to 2.3.
What type of attacks can CVE-2011-1001 facilitate?
CVE-2011-1001 can facilitate denial of service attacks and potentially allow arbitrary code execution.
Can CVE-2011-1001 be exploited remotely?
CVE-2011-1001 can be exploited by user-assisted remote attackers using a malformed APK or dex file.