Android libstagefright still exploitable
blog.exodusintel.com
Android libstagefright still exploitable
1–10 of 150 posts
Re: Android libstagefright still exploitable
#2Is this still responsible disclosure if they give Google basically 6 days to respond and use the original notification date as justification? I'm not learned enough in the practice of responsible disclosure to know if this is common, but I've not seen that before.
Re: Android libstagefright still exploitable
#3http://www.extremetech.com/mobile/197346-google-throws-nearl...
Re: Android libstagefright still exploitable
#4It always seemed likely that Google's hubris[1] would come back to haunt them. I guess this is that day.
It would be funny if it wasn't remote code execution affecting 950 million phones, with no official patch in sight.
Re: Android libstagefright still exploitable
#5Did I read that right? They reported the bug to Google on August 7th and disclosed it publicly on August 13th? Is this still responsible disclosure if they give Google basically 6 days to respond and use the original notification date as justification? I'm not learned enough in the practice of responsible disclosure to know if this is common, but I've not seen that before.
Re: Android libstagefright still exploitable
#6>Deadline exceeded – automatically derestricting >The flaw was initially reported over 120 days ago to Google, which exceeds even their own 90-day disclosure deadline. It always seemed likely that Google's hubris[1] would come back to haunt them. I guess this is that day. It would be funny if it wasn't remote code execution affecting 950 million phones, with no official patch in sight. [1] https://news.ycombinator.co…
Re: Android libstagefright still exploitable
#7You can partially mitigate the risk by disabling auto-downloading of MMS messages in whichever app you have set to handle text messages, such as Messaging or Hangouts. If you have not done so already, this is urgent. Furthermore, you should assume that auto-downloading of MMS messages will not ever be safe, no matter how many individual security fixes are applied, until this component of Android is significantly re-architected.
Re: Android libstagefright still exploitable
#8>Deadline exceeded – automatically derestricting >The flaw was initially reported over 120 days ago to Google, which exceeds even their own 90-day disclosure deadline. It always seemed likely that Google's hubris[1] would come back to haunt them. I guess this is that day. It would be funny if it wasn't remote code execution affecting 950 million phones, with no official patch in sight. [1] https://news.ycombinator.co…
[0] http://googleprojectzero.blogspot.com/2015/02/feedback-and-d...
Re: Android libstagefright still exploitable
#9April 2015 - Original stagefright exposed
July 31st - Author noticed patch was not sufficient but could not test (did not notify google)
August 6th - Patch released
August 7th - Author notified google that patch was not adequate
August 13th - Author went public?!?!
They are counting the original date of exploitation as the start date for notification. I would think a more responsible and friendly date would be August 7th. Just me.
Re: Android libstagefright still exploitable
#10Did I read that right? They reported the bug to Google on August 7th and disclosed it publicly on August 13th? Is this still responsible disclosure if they give Google basically 6 days to respond and use the original notification date as justification? I'm not learned enough in the practice of responsible disclosure to know if this is common, but I've not seen that before.