First published: Mon Apr 18 2011(Updated: )
Skype for Android stores sensitive user data without encryption in sqlite3 databases that have weak permissions, which allows local applications to read user IDs, contacts, phone numbers, date of birth, instant message logs, and other private information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Skype for Android |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-1717 is considered a high severity vulnerability due to improper handling of sensitive user data.
To fix CVE-2011-1717, update Skype for Android to the latest version where the vulnerability has been addressed.
CVE-2011-1717 exposes sensitive user data such as user IDs, contacts, phone numbers, and instant message logs.
Users of Skype for Android are affected by CVE-2011-1717 due to the lack of data encryption.
There is no effective workaround for CVE-2011-1717 other than updating to the patched version of Skype for Android.