ASB-A-185126149

See a problem?
Import Source
https://storage.googleapis.com/android-osv/ASB-A-185126149.json
JSON Data
https://api.osv.dev/v1/vulns/ASB-A-185126149
Aliases
  • A-185126149
  • CVE-2021-0642
Published
2021-08-01T00:00:00Z
Modified
2024-08-07T19:29:01.275407Z
Summary
Sensitive Iccid could be Sniffed by Intercepting ACTION_CONFIGURE_VOICEMAIL Implicit Intent in VoicemailSettingsFragment of Dialer
Details

In onResume of VoicemailSettingsFragment.java, there is a possible way to retrieve a trackable identifier without permissions due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.

References

Affected packages

Android / platform/packages/services/Telephony

Affected ranges

Type
ECOSYSTEM
Events
Introduced
8.1:0
Fixed
8.1:2021-08-01

Affected versions

8.*

8.1

Ecosystem specific

{
    "fixes": [
        "https://android.googlesource.com/platform/packages/services/Telephony/+/5cd723c11bfe29dd44e7fcdc730c945d7348f3b6"
    ],
    "spl": "2021-08-01",
    "severity": "High",
    "types": [
        "ID"
    ]
}

Android / platform/packages/services/Telephony

Affected ranges

Type
ECOSYSTEM
Events
Introduced
9:0
Fixed
9:2021-08-01

Affected versions

Other

9

Ecosystem specific

{
    "fixes": [
        "https://android.googlesource.com/platform/packages/services/Telephony/+/5cd723c11bfe29dd44e7fcdc730c945d7348f3b6"
    ],
    "spl": "2021-08-01",
    "severity": "High",
    "types": [
        "ID"
    ]
}

Android / platform/packages/services/Telephony

Affected ranges

Type
ECOSYSTEM
Events
Introduced
10:0
Fixed
10:2021-08-01

Affected versions

Other

10

Ecosystem specific

{
    "fixes": [
        "https://android.googlesource.com/platform/packages/services/Telephony/+/5cd723c11bfe29dd44e7fcdc730c945d7348f3b6"
    ],
    "spl": "2021-08-01",
    "severity": "High",
    "types": [
        "ID"
    ]
}

Android / platform/packages/services/Telephony

Affected ranges

Type
ECOSYSTEM
Events
Introduced
11:0
Fixed
11:2021-08-01

Affected versions

Other

11

Ecosystem specific

{
    "fixes": [
        "https://android.googlesource.com/platform/packages/services/Telephony/+/5521d7fce31260abde0b877ef9972658d87963fe"
    ],
    "spl": "2021-08-01",
    "severity": "High",
    "types": [
        "ID"
    ]
}