Access member only content, take part in discussions with comments on blogs, news and reviews and receive all the latest security industry news directly to your inbox. Join now for free.
A confirmation email has been sent to your email address - SUPPLIED EMAIL HERE. Please click on the link in the email to verify your email address. You need to verify your email before you can start posting.
If you do not receive your confirmation email within the next few minutes, it may be because the email has been captured by a junk mail filter. Please ensure you add the domain @scmagazine.com.au to your white-listed senders.
Security researchers have disclosed two new vulnerabilities in Google’s Android mobile platform which could lead to denial-of-service attacks.The Open Source Computer Emergency Response Team (oCert) warned of two flaws in version 1.5 of the increasingly popular platform, both of which have been patched by Google.The first involves Android’s handling of SMS messages, according to the oCert advisory. “A specific malformed SMS message can be crafted to trigger a condition that disconnects the mobile phone from the cellular network,” read the advisory.“The malformed SMS message consists of a badly formatted WAP Push message which causes an Java ArrayIndexOutOfBoundsException in the phone application (android.com.phone).”The phone application then silently reboots, leading to temporary loss of connectivity and dropped calls. If the phone’s SIM is protected by a PIN, users will be required to re-enter this, causing more delays and inconvenience, and if the bug is triggered repeatedly it could lead to DoS, said oCert.The second flaw is a DoS vulnerability in Android’s Dalvik API. “A specific malicious application can be crafted so that if it is downloaded and executed by the user, it would trigger the vulnerable API function and restart the system process,” said oCert.“The same condition could occur if a developer unintentionally places the vulnerable function in a place where the execution path leads to that function call. Triggering this bug is considered a DoS condition.”
To begin commenting right away, you can log in below or register an account if you don't yet have one. Please read our guidelines on commenting. Offending posts will be removed and your access may be suspended. Abusive or obscene language will not be tolerated. The comments below do not necessarily reflect the views or opinions of SC Magazine, Haymarket Media or its employees.