First published: Wed Jan 25 2012(Updated: )
The Xiaomi MiTalk Messenger (com.xiaomi.channel) application before 2.1.320 for Android does not properly protect data, which allows remote attackers to read or modify messaging information via a crafted application.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Xiaomi MiTalk Messenger | <=2.1.310 | |
Xiaomi MiTalk Messenger | =1.0 | |
Xiaomi MiTalk Messenger | =2.1.280 | |
Android Android |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-4697 has a moderate severity rating due to its potential to allow unauthorized access to sensitive messaging data.
To fix CVE-2011-4697, upgrade the Xiaomi MiTalk Messenger to version 2.1.320 or later.
CVE-2011-4697 affects Xiaomi MiTalk Messenger versions prior to 2.1.320, including 1.0, 2.1.280, and 2.1.310.
CVE-2011-4697 can be exploited by remote attackers to read or modify messaging information from the application.
No, the Android operating system itself is not directly affected by CVE-2011-4697, only the Xiaomi MiTalk Messenger app is impacted.