CVE-2011-2344
Android 2.x-3.0 - Unauthenticated Authentication Token Exposure via Cleartext HTTP Transmission
Title source: llmDescription
Android Picasa in Android 3.0 and 2.x through 2.3.4 uses a cleartext HTTP session when transmitting the authToken obtained from ClientLogin, which allows remote attackers to gain privileges and access private pictures and web albums by sniffing the token from connections with picasaweb.google.com.
References (3)
Core 3
Core References
Patch x_refsource_confirm
http://android.git.kernel.org/?p=platform/packages/apps/Gallery3D.git%3Ba=commit%3Bh=9a418de454e5ce078c98f41b5c18e3bb9175bd20
Patch x_refsource_confirm
http://android.git.kernel.org/?p=platform/packages/apps/Gallery3D.git%3Ba=commit%3Bh=7a763db1c15bb6436be85a3f23382e4171970b6e
Various Sources x_refsource_misc
http://www.uni-ulm.de/en/in/mi/staff/koenings/catching-authtokens.html
Scores
EPSS
0.0115
EPSS Percentile
63.5%
Details
CWE
CWE-310
Status
published
Products (8)
google/android
2.1
google/android
2.2 (2 CPE variants)
google/android
2.2.1
google/android
2.2.2
google/android
2.3 rev1
google/android
2.3.3
google/android
2.3.4
google/android
3.0
Published
Jul 08, 2011
Tracked Since
Feb 18, 2026