Se afișează postările cu eticheta flaw. Afișați toate postările
Se afișează postările cu eticheta flaw. Afișați toate postările

duminică, 25 ianuarie 2015

​Google leaves most Android users exposed to hackers

An executive confirms Google has no plans to fix a security hole in the default browser for older versions of Android, which are relied on by around 60 percent of all Android users.

People with Android smartphones and tablets running older versions of the mobile operating system -- around 60 percent of all Android users -- are going to have to live with a security flaw Google has decided not to fix.
A known security bug in the default, unbranded Web browser for Android 4.3 Jelly Bean and older versions of Google's mobile OS will go unpatched, Google's chief of security for Android wrote in a Google+ post on Friday.
"Keeping software up to date is one of the greatest challenges in security," Adrian Ludwig wrote. Because the browser app is based on a version of the WebKit browser engine that's now more than two years old, fixing the vulnerability in Android Jelly Bean and earlier versions is "no longer practical to do safely," he wrote.
Google confirmed on Saturday that Ludwig's post is the company's official position on the matter.

Source:

vineri, 23 ianuarie 2015

VLC vulnerabilities exposed

Summary:Major memory corruption vulnerabilities have been discovered in the open-source VLC project.

Vulnerabilities have been discovered in some versions of the popular VLC media player which may allow a cyberattacker to corrupt memory and potentially execute arbitrary code.








According to security researcher Veysel Hatas, who posted the discovery on Full Disclosure last week, one of the vulnerabilities is a DEP access violation vulnerability and the other is a write access flaw.

The VideoLAN project is a community of non-profit developers who create open-source multimedia tools. The VLC player is one of the most well-known results of this project, and acts as a cross-platform multimedia player and framework that plays most multimedia files as well as DVDs, Audio CDs, VCDs, and various streaming protocols.






The first security vulnerability, discovered on 24 November last year, is a flaw which is triggered as user-supplied input is not properly sanitized when handling a specially crafted FLV file.

Source:
http://www.zdnet.com/article/vlc-vulnerabilities-exposed/

Postări populare