PT-2011-4787 · Htc+1 · Htc Devices+1

Egzthunder1

+2

·

Publicado

2011-10-03

·

Atualizado

2017-08-29

·

CVE-2011-3975

CVSS v2.0

2.6

Baixa

VetorAV:N/AC:H/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions HTC devices with Android 2.3.4 build GRJ22
Description The issue allows user-assisted remote attackers to obtain sensitive information, including a list of telephone numbers from a log, by leveraging the android.permission.INTERNET application permission. This is achieved by establishing TCP sessions to 127.0.0.1 on port 65511 and a second port. The HtcLoggers.apk application, provided by a certain HTC update, is the vulnerable component.
Recommendations For HTC devices with Android 2.3.4 build GRJ22, consider restricting the use of the HtcLoggers.apk application until a patch is available. As a temporary workaround, restrict access to the android.permission.INTERNET application permission to minimize the risk of exploitation. Avoid establishing TCP sessions to 127.0.0.1 on port 65511 and the second port used by the HtcLoggers.apk application.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2011-3975

Produtos afetados

Android
Htc Devices