Latest Comments
"I too have been a labor voter for many years and will not be voting for them again. The ..."
by maxt | Feb 9, 2010 7:56 PM
 
"I’ve just had a user receive a rehashed version of this with an attached html file containing a ..."
by Owen Lutz | Feb 9, 2010 6:01 PM
 
"hi"
by manish kumar | Feb 9, 2010 4:27 PM
 
"Hey 'hey con-roy' ... from Google Australia's head of policy Iarla Flynn"We don't believe that ..."
by Keep it real | Feb 9, 2010 3:33 PM
 
"@penno Off-site storage is a good solution unless you have some decent backup software to ..."
by Charmgene | Feb 9, 2010 2:36 PM

Google Android vulnerabilities disclosed

  • Email a Friend
  • Print Page
Google Android vulnerabilities disclosed
By Phil Muncaster
Oct 12, 2009 9:40 AM
Tags: application | dos | function | lead | message | phone
Flaws could lead to denial of service.

Security researchers have disclosed two new vulnerabilities in Google’s Android mobile platform which could lead to denial-of-service attacks.

The Open Source Computer Emergency Response Team (oCert) warned of two flaws in version 1.5 of the increasingly popular platform, both of which have been patched by Google.

The first involves Android’s handling of SMS messages, according to the oCert advisory.

“A specific malformed SMS message can be crafted to trigger a condition that disconnects the mobile phone from the cellular network,” read the advisory.

“The malformed SMS message consists of a badly formatted WAP Push message which causes an Java ArrayIndexOutOfBoundsException in the phone application (android.com.phone).”

The phone application then silently reboots, leading to temporary loss of connectivity and dropped calls. If the phone’s SIM is protected by a PIN, users will be required to re-enter this, causing more delays and inconvenience, and if the bug is triggered repeatedly it could lead to DoS, said oCert.

The second flaw is a DoS vulnerability in Android’s Dalvik API. “A specific malicious application can be crafted so that if it is downloaded and executed by the user, it would trigger the vulnerable API function and restart the system process,” said oCert.

“The same condition could occur if a developer unintentionally places the vulnerable function in a place where the execution path leads to that function call. Triggering this bug is considered a DoS condition.”

Copyright © 2009 v3.co.uk

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
 
Vulnerabilities & Exploits Whitepapers