Security Advisory

CVE-2011-2344

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2011-07-08 17:00:00
Last updated 2024-09-16 18:49:52
Assigner Chrome
CVSS score not scored
State PUBLISHED

Description

Android Picasa in Android 3.0 and 2.x through 2.3.4 uses a cleartext HTTP session when transmitting the authToken obtained from ClientLogin, which allows remote attackers to gain privileges and access private pictures and web albums by sniffing the token from connections with picasaweb.google.com.