Vulnerability Abstract

Title: Vulnerability in GO SMS Pro for Android
Time: 01 Mar 2012
Author: Daoyuan Wu*, Xiapu Luo* and Rocky K. C. Chang
Department of Computing, The Hong Kong Polytechnic University, Hong Kong
* authors with equal contributions
CVE ID: CVE-2012-1393
Category: Newly Confirmed
Related Vendor: GO Dev Team

Application Information

Archive Time: Mar 1, 2012 at 10:57 PM HKT
Package Name: com.jb.gosms
Full Name: GO SMS Pro
Affected Version: 3.72, 4.10 and 4.35 (the latest version in 01 Mar 2012)
Package Installs: 10,000,000 - 50,000,000
Market Link: https://market.android.com/details?id=com.jb.gosms
Update Log: 4.36, the latest version in Mar 8 2012, also has this vulnerability!

Vulnerability Details

Status: Details only release to related vendor.

Vendor Response

Contact Time: Mar 2, 2012 at 8:05 PM HKT
Confirm Time: Mar 5, 2012 at 9:55 PM HKT
Patched Time: Unknown
Patched Status: Unknown

Important Notes

Although we only mention one or several affected version in our report, other versions may also be vulnerable, e.g. lower version, pad version or paid version.

Related Vulnerabilities