Vulnerability Abstract

Title: Vulnerability in Youdao Dictionary (有道字典) for Android
Time: 29 Feb 2012
Author: Daoyuan Wu*, Xiapu Luo* and Rocky K. C. Chang
Department of Computing, The Hong Kong Polytechnic University, Hong Kong
* authors with equal contributions
CVE ID: CVE-2012-1382
Category: Newly Released
Related Vendor: NetEase.com, Inc.

Application Information

Archive Time: Feb 29, 2012 at 5:48 PM HKT
Package Name: com.youdao.dict
Full Name: Youdao Dictionary (有道字典)
Affected Version: 1.6.1 and 2.0.1(2) (the latest version in 29 Feb 2012)
Package Installs: 500,000 - 1,000,000
Market Link: https://market.android.com/details?id=com.youdao.dict
Update Log: 3.0.0(1), the latest version in Mar 5 2012 HKT, also has this vulnerability!

Vulnerability Details

Status: Details only release to related vendor.

Vendor Response

Contact Time: Feb 29, 2012 at 8:12 PM HKT
Confirm Time: Mar 2, 2012 at 3:44 PM HKT
Patched Time: March 13, 2012
Patched Status: Has patched the vulnerability in version 3.0.1(1).

Important Notes

Although we only mention one or several affected version in our report, other versions may also be vulnerable, e.g. lower version, pad version or paid version.

Related Vulnerabilities