Overview
Stagefright is the media playback service for Android, introduced in Android 2.2 (Froyo). Stagefright in versions of Android prior to 5.1.1_r9 may contain multiple vulnerabilities, including several integer overflows, which may allow a remote attacker to execute code on the device.
Description
According to a Zimperium zLabs blog post, Android's Stagefright engine contains multiple vulnerabilities, including several integer overflows, allowing a remote attacker to access files or possibly execute code on the device. This vulnerability may at least partially affect all versions of Android starting from 2.2 (Froyo) and prior to 5.1.1_r9 (Lollipop).
An attacker with a victim's cell phone number may send maliciously crafted multimedia messages (MMS) which may be improperly parsed by the Stagefright tool. Other attack vectors may be possible.
According to Ars Technica, "successful exploits at the very least provide direct access to a phone's audio and camera feeds and to the external storage ... many older phones grant elevated system privileges to Stagefright code, a design that could allow attackers access to many more device resources."
Zimperium has released more information on these vulnerabilities, including a proof of concept code, patches, a video demoing the exploit and an Android app that detects the vulnerability.
The vulnerabilities include:
Code:
1. CVE-2015-1538, P0006, Google Stagefright stsc MP4 Atom Integer Overflow Remote Code Execution
2. CVE-2015-1538, P0004, Google Stagefright ctts MP4 Atom Integer Overflow Remote Code Execution
3. CVE-2015-1538, P0004, Google Stagefright stts MP4 Atom Integer Overflow Remote Code Execution
4. CVE-2015-1538, P0004, Google Stagefright stss MP4 Atom Integer Overflow Remote Code Execution
5. CVE-2015-1539, P0007, Google Stagefright esds MP4 Atom Integer Underflow Remote Code Execution
6. CVE-2015-3827, P0008, Google Stagefright covr MP4 Atom Integer Underflow Remote Code Execution
7. CVE-2015-3826, P0009, Google Stagefright 3GPP Metadata Buffer Overread
8. CVE-2015-3828, P0010, Google Stagefright 3GPP Integer Underflow Remote Code Execution
9. CVE-2015-3824, P0011, Google Stagefright tx3g MP4 Atom Integer Overflow Remote Code Execution
10. CVE-2015-3829, P0012, Google Stagefright covr MP4 Atom Integer Overflow Remote Code ExecutionImpact
A remote attacker may be able to execute code on the Android device.
Solution
- Apply an update
- Flash attached fix
This fix has been test successfully on POF3 international stock firmware
Now you would be able to test your device vulnerability using any of these apps: Stagefright Detector App or Stagefright Detector
Vulnerable

Safe (after flashing the patch)

Safe (after flashing the patch)
Source: zimperium
Aucun commentaire:
Enregistrer un commentaire