Saturday November 22, 2008 6:14 AM AEST
Latest Comments
"when i login to face book it tells me i am cookies enabled what does this mean"
by celeste | Nov 21, 2008 5:15 PM
 
"Hi this is the mail I received Brett Karpman show details Nov 17 (3 days ago) Reply Atten..."
by Rodney Churchyard | Nov 20, 2008 6:13 PM
 
"security through obscurity...shows how detached HIPAA is from reality."
by priceOfFishInChina | Nov 20, 2008 1:19 PM
 
"Umm. no. The 6.5 product is mounting the offline VM image and performing a scan for patch ..."
by eric | Nov 20, 2008 8:15 AM
 
"it's great i tried it"
by divyacharan | Nov 20, 2008 12:24 AM

Motorola RAZR vulnerable to JPEG attack

  • Email a Friend
  • Print Page
Motorola RAZR vulnerable to JPEG attack
By Richard Thurston
May 30, 2008 9:58 AM
Tags: Motorola | RAZR | found | vulnerable | to | JPEG | attack
Motorola's RAZR handset is vulnerable to downloading malware from a corrupted picture message, TippingPoint said on its vulnerability reporting service, Zero Day Initiative (ZDI).

Hackers are able to send a corrupt JPEG image to a RAZR which would run malicious code on the device if viewed, according to the ZDI advisory, released on Tuesday. Malicious code could force the device to make unwanted calls or send unwanted messages, for example.

The flaw exists in the JPEG thumbprint component of the EXIF parser. EXIF, or Exchangable Image File format, is a set of tags that can be embedded in image files, which might include the location where the image was taken or the camera used to take it.

When the user tries to view the image, a memory corruption is caused and malicious code can be run on the device.

Motorola was quoted on the advisory as saying: "Together, ZDI and Motorola have identified a potential vulnerability related to viewing malicious, manipulated JPEG files affecting select RAZR-series devices. Although the possibility of this vulnerability occurring is very remote and would only occur in unique circumstances, Motorola proactively corrected it in all new device releases."

The phone vendor urged RAZR users to download a firmware update from its website. Though the site insists users confirm that their device is under warranty, any users entering a date of purchase within the last 24 months are able to download the update.

Motorola has known about the vulnerability since July last year.

There are as yet few mobile viruses in existence - probably less than 400 - and many of these are proof of concept.

But many businesses are keeping a close watch on mobile exploits, particularly those which affect the major enterprise platforms.

Many of the anti-virus vendors now have a product which they claim will help to secure mobile devices against malware.

See original article on scmagazineus.com

Secure Computing Magazine

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
Tripwire - Click here to win an iTouch
 
 
 
Messaging Whitepapers