Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

'Stagefright 2.0' bug menaces over a billion Android devices
iTnews.com (AUS) ^ | Oct 2 2015 6:39AM (AUS) | Juha Saarinen

Posted on 10/01/2015 6:24:16 PM PDT by Utilizer

Researchers have discovered a second set of serious vulnerabilities in Google's Android mobile operating system, leaving over a billion new and old devices open to attack.

Dubbed Stagefright 2.0, the newly discovered vulnerabilities stem from two flaws in how Android handles audio and video files.

It was found by Joshua Drake of security vendor Zimperium, who also discovered the original Stagefright vulnerability affecting just under a billion Android devices in July this year.

The first Stagefright flaw in the Android media processing software library allowed attackers to send a specially crafted multimedia messaging service (MMS) missive which, when received in Google's Hangouts and Messenger apps, would allow attackers to run arbitrary code on victims devices without user interaction.

(Excerpt) Read more at itnews.com.au ...


TOPICS: Business/Economy; Computers/Internet
KEYWORDS: android; bug; os; stagefright; windowspinglist
More worrisome news for anyone using an Android device.
1 posted on 10/01/2015 6:24:16 PM PDT by Utilizer
[ Post Reply | Private Reply | View Replies]

To: Utilizer

Stagefright 1.0 performed by The Band in the film “The Last Waltz”:

https://www.youtube.com/watch?v=ZIfKkV77lqM


2 posted on 10/01/2015 6:27:14 PM PDT by ClearCase_guy (I've switched. Trump is my #1. He understands how to get things done. Cruz can be VP.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: ClearCase_guy

Putting my age on display - I was there when they taped it. I was stunned to see a DVD of it in a store labelled “Classics.”


3 posted on 10/01/2015 6:42:13 PM PDT by LoneStar42 ('The future ain't what it used to be.' Thanks, Yogi.)
[ Post Reply | Private Reply | To 2 | View Replies]

To: Utilizer

Great job Apple and Microsoft.


4 posted on 10/01/2015 6:55:25 PM PDT by A CA Guy ( God Bless America, God Bless and keep safe our fighting men and women.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Utilizer

Shockwave/Flash is malware for any device.


5 posted on 10/01/2015 8:03:59 PM PDT by Dalberg-Acton
[ Post Reply | Private Reply | To 1 | View Replies]

To: ThunderSleeps; dayglored; ShadowAce; Utilizer; ~Kim4VRWC's~; 1234; Abundy; Action-America; ...
This ping is for all you Android device users who may also be Apple device users. . . StageFright is back in a new incarnation and can infect even more Android devices. Estimate is 1 billion are vulnerable. Be careful out there. . .

Ping to the Apple list, ThunderSleeps to ping the Android list, dayglored for the Windows list, and Shadow Ace for the Tech list. . .


Be careful so your Android device doesn't come down sick!

6 posted on 10/01/2015 8:30:45 PM PDT by Swordmaker ( This tag line is a Microsoft insult free zone... but if the insults to Mac users continue...)
[ Post Reply | Private Reply | To 1 | View Replies]

To: 109ACS; aimhigh; bajabaja; Bikkuri; Bobalu; Bookwoman; Bullish; DarthDilbert; dayglored; ...
Be careful out there! — ANDROID PING!

Android Ping!
If you want on or off the Android Ping List, Freepmail me.

7 posted on 10/01/2015 9:18:42 PM PDT by ThunderSleeps (Stop obarma now! Stop the hussein - insane agenda!)
[ Post Reply | Private Reply | To 6 | View Replies]

To: Dalberg-Acton
Shockwave/Flash is malware for any device.

Unfortunately, it is used on many websites so browsers have to have ways to deal with it, and most smartphones use it as well which makes this bug doubly troublesome.

8 posted on 10/01/2015 9:19:34 PM PDT by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzlims trying to kill them)
[ Post Reply | Private Reply | To 5 | View Replies]

To: Swordmaker; Abby4116; afraidfortherepublic; aft_lizard; AF_Blue; Alas Babylon!; amigatec; ...
Android users beware - StageFright again ... PING!

You can find all the Windows Ping list threads with FR search: just search on keyword "windowspinglist".

This is for the Windows users who have Android devices -- you know who you are!

Thanks to Swordmaker for the ping!!

9 posted on 10/01/2015 9:26:18 PM PDT by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 6 | View Replies]

To: ThunderSleeps

The logo source file has moved or been deleted from its original location at http://ragzon.com/wp-content/uploads/2015/08/Android-logo-4.jpg

All one gets there is a 404.

You are going to have to find another Android robot logo. . .


10 posted on 10/01/2015 11:17:47 PM PDT by Swordmaker ( This tag line is a Microsoft insult free zone... but if the insults to Mac users continue...)
[ Post Reply | Private Reply | To 7 | View Replies]

To: ThunderSleeps
here you go:


http://www.ouyactu.com/media/2013/07/android.png

11 posted on 10/01/2015 11:22:52 PM PDT by Swordmaker ( This tag line is a Microsoft insult free zone... but if the insults to Mac users continue...)
[ Post Reply | Private Reply | To 10 | View Replies]

To: Utilizer
Oh, no, not really worrisome for Android users - good news, really. Potential bugs have been discovered because of the open source ecosystem of Android, those potential bugs will be addressed, and even more pressure put on handset makers and carriers to actually push out regular updates to the software.

Since Google has gone to a monthly update scheme for the Nexus line, they've set a new standard for the Android industry, one which will also pressure handset makers and carriers to follow along in the not so distant future.

Beyond, it shows the problem with carrier locked devices; users are kept from needed updates by this unnecessary restriction.

I expect that Dolphin will likely be one of the first browsers to use alternate libraries for mp3 & mp4 files, and an update to Google Chrome (and the dependent libraries) will be pushed out with the Marshmallow release.

It is to be noted that these are lab discovered vulnerabilities and no exploits of a 5 year old problem have ever been found in the wild, plus any Android device with 4.0 or higher uses randomized memory locations, so turning this exploit into something useful is rather doubtful to begin with.

12 posted on 10/01/2015 11:40:44 PM PDT by kingu (Everything starts with slashing the size and scope of the federal government.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Swordmaker

Got it, thanks. I’ll give it a try next ping!


13 posted on 10/02/2015 5:50:17 AM PDT by ThunderSleeps (Stop obarma now! Stop the hussein - insane agenda!)
[ Post Reply | Private Reply | To 11 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson