SB2014121501 - Permissions, Privileges, and Access Controls in Google, Google Android 



SB2014121501 - Permissions, Privileges, and Access Controls in Google, Google Android

Published: December 15, 2014 Updated: August 9, 2020

Security Bulletin ID SB2014121501
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2014-8610)

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

AndroidManifest.xml in Android before 5.0.0 does not require the SEND_SMS permission for the SmsReceiver receiver, which allows attackers to send stored SMS messages, and consequently transmit arbitrary new draft SMS messages or trigger additional per-message charges from a network operator for old messages, via a crafted application that broadcasts an intent with the com.android.mms.transaction.MESSAGE_SENT action, aka Bug 17671795.


Remediation

Install update from vendor's website.