Title: |
Vulnerability in Limit My Call for Android |
Time: |
07 Dec 2011 |
Author: |
Daoyuan Wu*, Xiapu Luo* and Rocky K. C. Chang |
|
Department of Computing, The Hong Kong Polytechnic University, Hong Kong |
|
* authors with equal contributions |
CVE ID: |
CVE-2011-4703 |
Category: |
Newly Released
|
Related Vendor: |
Nathaniel Kh |
Archive Time: |
December 7, 2011 HKT |
Package Name: |
com.limited.call.view |
Full Name: |
Limit My Call |
Affected Version: |
2.11 (the latest version in 07 Dec 2011) |
Package Installs: |
50,000 - 100,000 |
Market Link: |
https://market.android.com/details?id=com.limited.call.view |
Status: |
Breif impact description now releases to public.
|
Breif Description: |
Allows a malicious application to access and manipulate user’s contacts and corresponding calling logs. |
Contact Time: |
Dec 16, 2011 at 3:10 PM HKT
|
Confirm Time: |
Dec 18, 2011 at 8:36 AM HKT |
Patched Time: |
They didn't notied us about detailed patch time and version. |
Patched Status: |
We've checked version 2.12, uploaded in Feb 11 2012, which has patched the vulnerability. |
Although we only mention one or several affected version in our report, other versions may also be vulnerable, e.g. lower version, pad version or paid version.