Cryptographic issues in Google Android - CVE-2011-2344

 

Cryptographic issues in Google Android - CVE-2011-2344

Published: July 8, 2011 / Updated: August 11, 2020


Vulnerability identifier: #VU44896
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2011-2344
CWE-ID: CWE-310
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

Android Picasa in Android 3.0 and 2.x through 2.3.4 uses a cleartext HTTP session when transmitting the authToken obtained from ClientLogin, which allows remote attackers to gain privileges and access private pictures and web albums by sniffing the token from connections with picasaweb.google.com.


Affected software

Google Android

How to mitigate CVE-2011-2344

Install update from vendor's website.


External References

Related Security Bulletins