CVE-2011-4772: Medium severity 360 kouxin vulnerability
Published Jan 25, 2012
·Updated
The 360 KouXin (com.qihoo360.kouxin) application 1.5.3 for Android does not properly protect data, which allows remote attackers to read or modify SMS messages and a contact list via a crafted application.
Affected Software
2 affected components
360 KouXin=1.5.3
Android Android
Event History
Jan 25, 2012
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Data Sourced
04:03 AM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2011-4772?
The severity of CVE-2011-4772 is considered to be high due to the potential for remote attackers to access sensitive data.
2
How do I fix CVE-2011-4772?
To fix CVE-2011-4772, update the 360 KouXin application to the latest version available.
3
What type of data is vulnerable in CVE-2011-4772?
CVE-2011-4772 exposes SMS messages and the contact list to unauthorized access and modification.
4
What versions of the 360 KouXin application are affected by CVE-2011-4772?
Only version 1.5.3 of the 360 KouXin application is affected by CVE-2011-4772.
5
Is the Android operating system itself vulnerable in CVE-2011-4772?
No, the vulnerability in CVE-2011-4772 is specific to the 360 KouXin application and not the Android operating system.