PT-2011-4787 · Htc+1 · Htc Devices+1
Egzthunder1
+2
·
Publicado
2011-10-03
·
Atualizado
2017-08-29
·
CVE-2011-3975
CVSS v2.0
2.6
Baixa
| Vetor | AV:N/AC:H/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
HTC devices with Android 2.3.4 build GRJ22
Description
The issue allows user-assisted remote attackers to obtain sensitive information, including a list of telephone numbers from a log, by leveraging the android.permission.INTERNET application permission. This is achieved by establishing TCP sessions to 127.0.0.1 on port 65511 and a second port. The HtcLoggers.apk application, provided by a certain HTC update, is the vulnerable component.
Recommendations
For HTC devices with Android 2.3.4 build GRJ22, consider restricting the use of the HtcLoggers.apk application until a patch is available. As a temporary workaround, restrict access to the android.permission.INTERNET application permission to minimize the risk of exploitation. Avoid establishing TCP sessions to 127.0.0.1 on port 65511 and the second port used by the HtcLoggers.apk application.
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Android
Htc Devices