PT-2012-4410 · Google · Android
Glenn Ten Cate
·
Published
2012-08-21
·
Updated
2012-08-21
·
CVE-2012-2980
CVSS v2.0
7.1
High
| Vector | AV:N/AC:M/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Android (affected versions not specified) on T-Mobile myTouch 3G Slide, HTC Merge, Sprint EVO Shift 4G, HTC ChaCha, AT&T Status, HTC Desire Z, T-Mobile G2, T-Mobile myTouch 4G Slide, and Samsung Galaxy S
Description
The onTouchEvent method implementation for Android on certain devices stores touch coordinates in the dmesg buffer. This allows remote attackers to obtain sensitive information, such as PIN numbers, telephone numbers, and text messages, via a crafted application.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Android