First published: Wed Mar 19 2014(Updated: )
The NTT DOCOMO sp mode mail application 6300 and earlier for Android 4.0.x and 6700 and earlier for Android 4.1 through 4.4 uses weak permissions for attachments during processing of incoming e-mail messages, which allows attackers to obtain sensitive information via a crafted application.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Nttdocomo Spmode Mail Android | <=6300 | |
Nttdocomo Spmode Mail Android | =2546 | |
Nttdocomo Spmode Mail Android | =2631 | |
Nttdocomo Spmode Mail Android | =3000 | |
Nttdocomo Spmode Mail Android | =3100 | |
Nttdocomo Spmode Mail Android | =3200 | |
Nttdocomo Spmode Mail Android | =3300 | |
Nttdocomo Spmode Mail Android | =3400 | |
Nttdocomo Spmode Mail Android | =4000 | |
Nttdocomo Spmode Mail Android | =4200 | |
Nttdocomo Spmode Mail Android | =4300 | |
Nttdocomo Spmode Mail Android | =4400 | |
Nttdocomo Spmode Mail Android | =4500 | |
Nttdocomo Spmode Mail Android | =4600 | |
Nttdocomo Spmode Mail Android | =4700 | |
Nttdocomo Spmode Mail Android | =4800 | |
Nttdocomo Spmode Mail Android | =4900 | |
Nttdocomo Spmode Mail Android | =5000 | |
Nttdocomo Spmode Mail Android | =5100 | |
Nttdocomo Spmode Mail Android | =5200 | |
Nttdocomo Spmode Mail Android | =5300 | |
Nttdocomo Spmode Mail Android | =5400 | |
Nttdocomo Spmode Mail Android | =5500 | |
Nttdocomo Spmode Mail Android | =5550 | |
Google Android | =4.0 | |
Google Android | =4.0.1 | |
Google Android | =4.0.2 | |
Google Android | =4.0.3 | |
Google Android | =4.0.4 | |
Nttdocomo Spmode Mail Android | <=6700 | |
Google Android | =4.1 | |
Google Android | =4.1.2 | |
Google Android | =4.2 | |
Google Android | =4.2.1 | |
Google Android | =4.2.2 | |
Google Android | =4.3 | |
Google Android | =4.3.1 | |
Google Android | =4.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-1977 is considered a moderate severity vulnerability due to the weak permissions for attachments in the application.
To fix CVE-2014-1977, it is recommended to update the NTT DOCOMO sp mode mail application to the latest version available.
CVE-2014-1977 affects NTT DOCOMO sp mode mail application versions 6300 and earlier, as well as versions 6700 and earlier for Android 4.1 through 4.4.
CVE-2014-1977 allows attackers to obtain sensitive information via crafted email attachments, compromising user data.
No, CVE-2014-1977 is not a risk for current versions of the NTT DOCOMO sp mode mail application if kept up to date.