CVE-2011-4276: Infoleak
Published Jan 25, 2012
·Updated
The Bluetooth service (com/android/phone/BluetoothHeadsetService.java) in Android 2.3 before 2.3.6 allows remote attackers within Bluetooth range to obtain contact data via an AT phonebook transfer.
Affected Software
4 affected components
Google Android=2.3
Google Android=2.3.3
Google Android=2.3.4
Google Android=2.3.5
Event History
Jan 25, 2012
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-4276?
CVE-2011-4276 has a medium severity rating due to the potential data exposure through Bluetooth.
2
How do I fix CVE-2011-4276?
To mitigate CVE-2011-4276, users should upgrade their Android version to 2.3.6 or later.
3
What type of attack does CVE-2011-4276 enable?
CVE-2011-4276 allows remote attackers within Bluetooth range to access contact data via AT phonebook transfer.
4
Which versions of Android are affected by CVE-2011-4276?
CVE-2011-4276 affects Android versions 2.3, 2.3.3, 2.3.4, and 2.3.5.
5
Is CVE-2011-4276 a client-side or server-side vulnerability?
CVE-2011-4276 is considered a client-side vulnerability as it affects the Bluetooth service in Android devices.