Vulnerability Abstract

Title: Vulnerability in Scan to PDF for Android
Time: 14 Dec 2011
Author: Daoyuan Wu*, Xiapu Luo* and Rocky K. C. Chang
Department of Computing, The Hong Kong Polytechnic University, Hong Kong
* authors with equal contributions
CVE ID: CVE-2011-4771
Category: To Be Confirmed
Related Vendor: Nym Computing, http://melbina.free.fr/

Application Information

Archive Time: December 14, 2011 05:10:28 PM HKT
Package Name: com.scan.to.pdf.trial
Full Name: Scan to PDF Free
Affected Version: 2.0.4 (the latest version in 14 Dec 2011)
Package Installs: 100,000 - 500,000
Market Link: https://market.android.com/details?id=com.scan.to.pdf.trial

Vulnerability Details

Status: Breif impact description now releases to public.
Breif Description: Allow a malicious application to access and manipulate user’s Google account and scanned files.

Vendor Response

Contact Time: Dec 16, 2011 at 4:05 PM HKT
Confirm Time: No reply, although we have notified them.
Patched Time: Unknown
Patched Status: Unknown

Important Notes

Although we only mention one or several affected version in our report, other versions may also be vulnerable, e.g. lower version, pad version or paid version.

Related Vulnerabilities