Android SMS Spoofing Vulnerability
BID:56392
Info
Android SMS Spoofing Vulnerability
| Bugtraq ID: | 56392 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 05 2012 12:00AM |
| Updated: | Nov 05 2012 12:00AM |
| Credit: | Xuxian Jiang |
| Vulnerable: |
Google Android 3.1.4 Google Android 2.3.5 Google Android 2.2.3 Google Android 3.2 Google Android 3.0 Google Android 2.3.4 Google Android 2.3.3 Google Android 2.3.2 Google Android 2.3.1 Google Android 2.2.2 Google Android 2.2.1 Google Android 2.2 Google Android 2.1 Google Android 1.6 |
| Not Vulnerable: | |
Discussion
Android SMS Spoofing Vulnerability
Android is prone to an SMS-spoofing vulnerability.
An attacker may exploit this vulnerability to send spoofed SMS contents to a victim that seem to originate from a trusted user. This allows a remote attacker to carry out phishing attacks. Other attacks may be possible.
Android versions 1.6 (Donut) through 4.1 (Jelly Bean) are vulnerable.
Android is prone to an SMS-spoofing vulnerability.
An attacker may exploit this vulnerability to send spoofed SMS contents to a victim that seem to originate from a trusted user. This allows a remote attacker to carry out phishing attacks. Other attacks may be possible.
Android versions 1.6 (Donut) through 4.1 (Jelly Bean) are vulnerable.
Solution / Fix
Android SMS Spoofing Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]