CVE-2011-4705: Medium severity ming blacklist free vulnerability
Published Jan 25, 2012
·Updated
The Ming Blacklist Free (vc.software.blacklist) application 1.8.1 and 1.9.2.1 for Android does not properly protect data, which allows remote attackers to read or modify blacklists and a contact list via a crafted application that launches a "data-flow attack."
Affected Software
3 affected components
Ming Blacklist Free=1.8.1
Ming Blacklist Free=1.9.2.1
Android Android
Event History
Jan 25, 2012
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Data Sourced
04:03 AM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2011-4705?
CVE-2011-4705 has a medium severity rating due to its potential for data exposure and modification.
2
How do I fix CVE-2011-4705?
To fix CVE-2011-4705, users should update to a secure version of the Ming Blacklist Free application, if available.
3
What versions of Ming Blacklist Free are affected by CVE-2011-4705?
The affected versions of Ming Blacklist Free are 1.8.1 and 1.9.2.1.
4
Can CVE-2011-4705 be exploited remotely?
Yes, CVE-2011-4705 can be exploited remotely through a crafted application that performs a data-flow attack.
5
What type of data can be accessed due to CVE-2011-4705?
Due to CVE-2011-4705, attackers can read or modify the application’s blacklists and contact list.