First published: Wed Jan 25 2012(Updated: )
The Ming Blacklist Free (vc.software.blacklist) application 1.8.1 and 1.9.2.1 for Android does not properly protect data, which allows remote attackers to read or modify blacklists and a contact list via a crafted application that launches a "data-flow attack."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ming Blacklist Free | =1.8.1 | |
Ming Blacklist Free | =1.9.2.1 | |
Android Operating System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-4705 has a medium severity rating due to its potential for data exposure and modification.
To fix CVE-2011-4705, users should update to a secure version of the Ming Blacklist Free application, if available.
The affected versions of Ming Blacklist Free are 1.8.1 and 1.9.2.1.
Yes, CVE-2011-4705 can be exploited remotely through a crafted application that performs a data-flow attack.
Due to CVE-2011-4705, attackers can read or modify the application’s blacklists and contact list.