| Title: |
Vulnerability in QQPhoto (Q拍) for Android |
| Time: |
29 Dec 2011 |
| Author: |
Daoyuan Wu*, Xiapu Luo* and Rocky K. C. Chang |
|
Department of Computing, The Hong Kong Polytechnic University, Hong Kong |
|
* authors with equal contributions |
| CVE ID: |
CVE-2011-4867 |
| Category: |
Newly Released
|
| Related Vendor: |
Tencent, Inc. |
| Archive Time: |
December 29, 2011 at 9:22 PM HKT |
| Package Name: |
com.tencent.qqphoto |
| Full Name: |
QQPhoto ("Q拍" in Chinese name) |
| Affected Version: |
0.96 beta (the latest version in 29 Dec 2011) |
| Package Installs: |
5,000 – 10,000 |
| Market Link: |
https://market.android.com/details?id=com.tencent.qqphoto |
| Update Log: |
We made a mistake in Dec 29 2011 that the vulnerable version is 0.96 rather than 0.97! We are sorry for this error. |
| Status: |
Breif impact description now releases to public.
|
| Breif Description: |
Allow a malicious application to access and manipulate user’s private information (e.g., password’s MD5 value, contacts, cached data, and etc.) protected by QQPhoto. |
| Contact Time: |
Dec 31, 2011 at 2:54 PM HKT
|
| Confirm Time: |
Dec 31, 2011 at 6:08 PM HKT |
| Patched Time: |
January 4, 2012 HKT |
| Patched Status: |
Has patched the vulnerability in version 0.97 beta. |
Although we only mention one or several affected version in our report, other versions may also be vulnerable, e.g. lower version, pad version or paid version.