Executive Summary

Summary
Title Motorola Good Mobile Messaging insecure file deletion
Informations
Name VU#500963 First vendor Publication 2008-05-28
Vendor VU-CERT Last vendor Modification 2008-05-29
Severity (Vendor) N/A Revision M

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector :
Cvss Base Score N/A Attack Range N/A
Cvss Impact Score N/A Attack Complexity N/A
Cvss Expoit Score N/A Authentication N/A
Calculate full CVSS 2.0 Vectors scores

Detail

Vulnerability Note VU#500963

Motorola Good Mobile Messaging insecure file deletion

Overview

When formating removable storage cards, Motorola Good Mobile Messaging products may not properly delete old data.

I. Description

Motorola Good Mobile Messaging products can create encrypted containers on removable media storage cards. During the process of creating the container old information on storage card may not be properly deleted.

II. Impact

Private information may remain on the storage card. If the card is lost, stolen, or redistributed the information could be obtained by a third party.

III. Solution

We are currently unaware of a practical solution to this problem.

Securely wipe storage cards

Administrators should use a data deletion tool that fills storage cards with data (overwriting private information) prior to using the cards in Good Mobile products. A similar process should be used when disposing or redistributing the cards.

Systems Affected

VendorStatusDate Updated
Motorola, Inc.Vulnerable28-May-2008

References


http://www.good.com/corp/index.php
http://www.sysresccd.org/Sysresccd-manual-en_Secure_Deletion_of_Data
http://en.wikipedia.org/wiki/Data_remanence#Specific_methods

Credit

Thanks to Michael J. Iacovacci for reporting this vulnerability.

This document was written by Ryan Giobbi.

Other Information

Date Public03/24/2008
Date First Published05/28/2008 07:45:40 PM
Date Last Updated05/29/2008
CERT Advisory 
CVE Name 
US-CERT Technical Alerts 
Metric0.09
Document Revision13

Original Source

Url : http://www.kb.cert.org/vuls/id/500963