Vulnerability Abstract

Title: Vulnerability in NetEaseWeibo (网易微博) for Android
Time: 29 Feb 2012
Author: Daoyuan Wu*, Xiapu Luo* and Rocky K. C. Chang
Department of Computing, The Hong Kong Polytechnic University, Hong Kong
* authors with equal contributions
CVE ID: CVE-2012-1380
Category: Newly Released
Related Vendor: NetEase.com, Inc.

Application Information

Archive Time: Feb 29, 2012 at 4:29 PM HKT
Package Name: com.netease.wb
Full Name: NetEaseWeibo ("网易微博" in Chinese name)
Affected Version: 1.2.1 Build 2011-11-10 12:00 and 1.2.2 Build 2011-12-31 11:00 (the latest version in 29 Feb 2012)
Package Installs: 5,000 - 10,000
Market Link: https://market.android.com/details?id=com.netease.wb

Vulnerability Details

Status: Details only release to related vendor.

Vendor Response

Contact Time: Feb 29, 2012 at 8:05 PM HKT
Confirm Time: Mar 1, 2012 at 6:41 PM HKT
Patched Time: Mar 15, 2012
Patched Status: Has patched the vulnerability in version 1.2.3 Build 2012-03-14 18:00.

Important Notes

Although we only mention one or several affected version in our report, other versions may also be vulnerable, e.g. lower version, pad version or paid version.

Related Vulnerabilities