PT-2014-4400 · Ntt Docomo+1 · Ntt Docomo Sp Mode Mail+1
Hironori Tokuta
·
Published
2014-03-19
·
Updated
2014-03-20
·
CVE-2014-1978
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
NTT DOCOMO sp mode mail application versions 6100 through 6300 for Android 4.0.x
NTT DOCOMO sp mode mail application versions 6130 through 6700 for Android 4.1 through 4.4
Description
The issue allows attackers to obtain sensitive information via a crafted application, as the application link interface in the NTT DOCOMO sp mode mail application writes message content to the SD card during e-mail composition.
Recommendations
For versions 6100 through 6300, consider restricting access to the SD card to minimize the risk of exploitation.
For versions 6130 through 6700, avoid using the application for sensitive communications until a fix is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Android
Ntt Docomo Sp Mode Mail