PT-2014-4400 · Ntt Docomo+1 · Ntt Docomo Sp Mode Mail+1

Hironori Tokuta

·

Published

2014-03-19

·

Updated

2014-03-20

·

CVE-2014-1978

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions NTT DOCOMO sp mode mail application versions 6100 through 6300 for Android 4.0.x NTT DOCOMO sp mode mail application versions 6130 through 6700 for Android 4.1 through 4.4
Description The issue allows attackers to obtain sensitive information via a crafted application, as the application link interface in the NTT DOCOMO sp mode mail application writes message content to the SD card during e-mail composition.
Recommendations For versions 6100 through 6300, consider restricting access to the SD card to minimize the risk of exploitation. For versions 6130 through 6700, avoid using the application for sensitive communications until a fix is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-1978

Affected Products

Android
Ntt Docomo Sp Mode Mail