HTC Products Wi-Fi credential leakage Vulnerability
Release date:
Updated on:
Affected Systems:
HTC Desire HD
HTC Desire S
HTC Droid Incredible
Htc evo 3D
HTC Thunderbolt
Description:
--------------------------------------------------------------------------------
Cve id: CVE-2011-4872
HTC is a global mobile phone innovation and design company named HTC International Electronics Co., Ltd.
Among Multiple HTC products, the "WifiConfiguration: toString ()" method returns a plaintext Wi-Fi credential security vulnerability, which can be exploited by malicious users to leak sensitive information. Malicious applications must be installed with the "Android. permission. ACCESS_WIFI_STATE" permission.
<* Source: Chris Hessing
Link: http://www.kb.cert.org/vuls/id/763355
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
HTC
---
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.htc.com