CVE Vulnerabilities

CVE-2011-2344

Published: Jul 08, 2011 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Android Picasa in Android 3.0 and 2.x through 2.3.4 uses a cleartext HTTP session when transmitting the authToken obtained from ClientLogin, which allows remote attackers to gain privileges and access private pictures and web albums by sniffing the token from connections with picasaweb.google.com.

Affected Software

NameVendorStart VersionEnd Version
AndroidGoogle2.1 (including)2.1 (including)
AndroidGoogle2.2 (including)2.2 (including)
AndroidGoogle2.2-rev1 (including)2.2-rev1 (including)
AndroidGoogle2.2.1 (including)2.2.1 (including)
AndroidGoogle2.2.2 (including)2.2.2 (including)
AndroidGoogle2.3-rev1 (including)2.3-rev1 (including)
AndroidGoogle2.3.3 (including)2.3.3 (including)
AndroidGoogle2.3.4 (including)2.3.4 (including)
AndroidGoogle3.0 (including)3.0 (including)

References