Skype for Android stores sensitive user data without encryption in...
Vulnerability Description
Skype for Android stores sensitive user data without encryption in sqlite3 databases that have weak permissions, which allows local applications to read user IDs, contacts, phone numbers, date of birth, instant message logs, and other private information.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2011-1717
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.androidpolice.com/2011/04/14/exclusive-vulnerability-in-skype-for-android-is-exposing-your-name-phone-number-chat-logs-and-a-lot-more/
- http://blogs.skype.com/security/2011/04/privacy_vulnerability_in_skype.html
- http://www.theregister.co.uk/2011/04/15/skype_for_android_vulnerable/
- http://www.securitytracker.com/id?1025387
More from skype
View All →Affected Vendor
skype
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.