Skip to main content

Issues on Android "Stagefright" Media Library Remote Code Execution Vulnerabilities

Release Date: 28 Jul 2015 1880 Views

Recently, a security research company reported that remote code execution vulnerabilities were identified in Android smartphones. With these vulnerabilities, arbitrary code would be executed upon MMS message received on target smartphone.

 

Summary

  • ZIMPERIUM security research company [1] reported that remote code execution vulnerabilities were identified in Android media library "Stagefright".
  • The vulnerabilities affected Android 2.2 or later.
  • When the crafted MMS is received by the phone, arbitrary code could be executed without any user interaction.
  • Vendor patch is currently unavailable.

HKCERT has issued a security bulletin for the said vulnerabilities. Please refer to it for workaround solutions:

/my_url/alert/15072901

 

[1] Reference: http://blog.zimperium.com/experts-found-a-unicorn-in-the-heart-of-android/