Vulnerability Abstract

Title: Vulnerability in QQPhoto (Q拍) for Android
Time: 29 Dec 2011
Author: Daoyuan Wu*, Xiapu Luo* and Rocky K. C. Chang
Department of Computing, The Hong Kong Polytechnic University, Hong Kong
* authors with equal contributions
CVE ID: CVE-2011-4867
Category: Newly Released
Related Vendor: Tencent, Inc.

Application Information

Archive Time: December 29, 2011 at 9:22 PM HKT
Package Name: com.tencent.qqphoto
Full Name: QQPhoto ("Q拍" in Chinese name)
Affected Version: 0.96 beta (the latest version in 29 Dec 2011)
Package Installs: 5,000 – 10,000
Market Link: https://market.android.com/details?id=com.tencent.qqphoto
Update Log: We made a mistake in Dec 29 2011 that the vulnerable version is 0.96 rather than 0.97! We are sorry for this error.

Vulnerability Details

Status: Breif impact description now releases to public.
Breif Description: Allow a malicious application to access and manipulate user’s private information (e.g., password’s MD5 value, contacts, cached data, and etc.) protected by QQPhoto.

Vendor Response

Contact Time: Dec 31, 2011 at 2:54 PM HKT
Confirm Time: Dec 31, 2011 at 6:08 PM HKT
Patched Time: January 4, 2012 HKT
Patched Status: Has patched the vulnerability in version 0.97 beta.

Important Notes

Although we only mention one or several affected version in our report, other versions may also be vulnerable, e.g. lower version, pad version or paid version.

Related Vulnerabilities