First published: Wed Jan 25 2012(Updated: )
The Bluetooth service (com/android/phone/BluetoothHeadsetService.java) in Android 2.3 before 2.3.6 allows remote attackers within Bluetooth range to obtain contact data via an AT phonebook transfer.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Google Android | =2.3.3 | |
Google Android | =2.3.5 | |
Google Android | =2.3.4 | |
Google Android | =2.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-4276 has a medium severity rating due to the potential data exposure through Bluetooth.
To mitigate CVE-2011-4276, users should upgrade their Android version to 2.3.6 or later.
CVE-2011-4276 allows remote attackers within Bluetooth range to access contact data via AT phonebook transfer.
CVE-2011-4276 affects Android versions 2.3, 2.3.3, 2.3.4, and 2.3.5.
CVE-2011-4276 is considered a client-side vulnerability as it affects the Bluetooth service in Android devices.