CVE-2011-0680
Summary
| CVE | CVE-2011-0680 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2011-01-31 20:00:51 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | data/WorkingMessage.java in the Mms application in Android before 2.2.2 and 2.3.x before 2.3.2 does not properly manage the draft cache, which allows remote attackers to read SMS messages intended for other recipients in opportunistic circumstances via a standard text messaging service. |
Risk And Classification
Primary CVSS: v2.0 5 from [email protected]
AV:N/AC:L/Au:N/C:P/I:N/A:N
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:L/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Android | 1.5 | All | All | All | |
| Operating System | Android | 1.6 | All | All | All | |
| Operating System | Android | 2.1 | All | All | All | |
| Operating System | Android | 2.2 | rev1 | All | All | |
| Operating System | Android | 2.3 | rev1 | All | All | |
| Operating System | Android | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| android.git.kernel.org | af854a3a-2127-422b-91ae-364da2661108 | android.git.kernel.org | |
| Nexus One Update to Android 2.2.2 | af854a3a-2127-422b-91ae-364da2661108 | www.htcphones.net | |
| Sign in - Google Accounts | af854a3a-2127-422b-91ae-364da2661108 | code.google.com | |
| Android 2.3.2 Update Pushing to Nexus S Phone, Fixes SMS Bug | af854a3a-2127-422b-91ae-364da2661108 | phandroid.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Nexus S gets Android 2.3.2, fixes SMS bug | Samsung Hub | af854a3a-2127-422b-91ae-364da2661108 | www.samsunghub.com | |
| Open Handset Alliance Android 'data/WorkingMessage.java' Information Disclosure Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Sign in - Google Accounts | af854a3a-2127-422b-91ae-364da2661108 | code.google.com | |
| JavaScript is not available. | af854a3a-2127-422b-91ae-364da2661108 | twitter.com | |
| Nexus One gets tiny update to Android 2.2.2, fixes SMS routing issues -- Engadget | af854a3a-2127-422b-91ae-364da2661108 | www.engadget.com | |
| Google updates nexus one to android 2.2.2- The Inquirer | af854a3a-2127-422b-91ae-364da2661108 | www.theinquirer.net | Patch |
| android.git.kernel.org | af854a3a-2127-422b-91ae-364da2661108 | android.git.kernel.org | |
| CONFIRM:http://android.git.kernel.org/?p=platform/packages/apps/Mms.git;a=commit;h=18d6b7e9d2e538fb3c0264332b96c02abf367267 | MITRE | android.git.kernel.org | |
| MISC:http://android.git.kernel.org/?p=platform/packages/apps/Mms.git;a=commit;h=4d26623ce82230e8e7009adb921c5edea370a9e0 | MITRE | android.git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.