Maliciously Crafted MKV Video Files Can Be Used To Crash Android Phones
itwbennett writes: Just days after publication of a flaw in Android's Stagefright, which could allow attackers to compromise devices with a simple MMS message, researchers have found another Android media processing flaw. The latest vulnerability is located in Android's mediaserver component, more specifically in how the service handles files that use the Matroska video container (MKV), Trend Micro researchers said. "When the process opens a malformed MKV file, the service may crash (and with it, the rest of the operating system). The vulnerability is caused by an integer overflow when the mediaserver service parses an MKV file. It reads memory out of buffer or writes data to NULL address when parsing audio data."
Could this be used in a malicious way, other than annoying people by rebooting their phones?
And those running custom mods will have this fix this week while those who are locked in to their carriers will be stuck vulnerable for who knows how long.
Your hair look like poop, Bob! - Wanker.
Are the worst iPhones ever made...
with ants
Can someone explain why the program handling interaction with assorted media files would be so closely linked to the rest of the system working? I understand that parsing the ghastly mess of different standard and pseudo-standard formats out there, as poorly or even maliciously interpreted by various 3rd parties, is a difficult and dangerous task; so I'm not surprised by the fact that there is a bug in the media component; but if it is known to do such a dangerous job why isn't it compartmentalized more aggressively? Why does losing the mediaserver process make a mess of the phone, rather than just causing it to mark the file that killed it as tainted, restart the process, and carry on?
Somebody please explain to me why the crashing of a service for indexing media files can bring down the whole OS. Isn't that a userspace program? Why is it so embedded in the kernel or operating system that it crashes the whole device? Isn't that really bad practice? Are there any valid reasons to do it this way?
Except that you don't need an MKV - just look at it wrong while you're in the middle of editing your Plaid Times blog and it just reboots all by itself. My, that's a pretty Apple logo...I wonder if I'll have to re-type my whole story on aging skinny jeans when it comes back up? Whatever, I'm sure it rebooted for a reason. Oh look, I'm almost at the bottom of my vanilla half-caf all skim latte - I'll go get another while I wait for the phone to come back up.
Stop posting all those Windows 10 OMG!!! threads.
(-1: Post disagrees with my already-settled worldview) is not a valid mod option.
Hi,
I'm running Linux but it's crashing a lot and all the applications are useless and look terrible.
Is Windows 10 better than Linux?
Thanks...
--interested_user
Check out the new WINDOWS 10!!!!
Its free!!!!!!!!!
Its Windows 10!!!!!!!!!!!
It has a shiny new logo!!!!!!!!!!!!
It has 7 facts!!!!!
Its Windows!!!!!!!!
Its free!!!!!!!!
It LAUNCHES TODAY!!!!!!!!!!!!!!!!!
OMG, WINDOWS 10!!!!!!
Check out the new WINDOWS 10!!!!
Its free!!!!!!!!!
Its Windows 10!!!!!!!!!!!
It has a shiny new logo!!!!!!!!!!!!!!!!
It has 7 facts!!!!!
Its Windows!!!!!!!!
Its free!!!!!!!!
It LAUNCHES TODAY!!!!!!
OMG, WINDOWS 10!!!!!!
Check out the new WINDOWS 10!!!!
Its free!!!!!!!!!
Its Windows 10!!!!!!!!!!!
It has a shiny new logo!!!!!!!!!!!!!!!!
It has 7 facts!!!!!
Its Windows!!!!!!!!!!!
Its free!!!!!!!!
It LAUNCHES TODAY!!!!!!
OMG, WINDOWS 10!!!!!!
Check out the new WINDOWS 10!!!!
Its free!!!!!!!!!
Its Windows 10!!!!!!!!!!!
It has a shiny new logo!!!!!!!!!!!!!!!!
It has 7 facts!!!!!
Its Windows!!!!!!!!
Its free!!!!!!!!
It LAUNCHES TODAY!!!!!!
OMG, WINDOWS 10!!!!!!
Check out the new WINDOWS 10!!!!
Its free!!!!!!!!!
Its Windows 10!!!!!!!!!!!
It has a shiny new logo!!!!!!!!!!!!!!!!
It has 7 facts!!!!!
Its Windows!!!!!!!!!!
Its free!!!!!!!!
It LAUNCHES TODAY!!!!!!
OMG, WINDOWS 10!!!!!!
Check out the new WINDOWS 10!!!!
Its free!!!!!!!!!
Its Windows 10!!!!!!!!!!!
It has a shiny new logo!!!!!!!!!!!!!!!!
It has 7 facts!!!!!
Its Windows!!!!!!!!
Its free!!!!!!!!
It LAUNCHES TODAY!!!!!!
OMG, WINDOWS 10!!!!!!!!
This is a that? I rip a lot of vids to MKV and recently I've had problems with 3 , files that crash my tablet it phone. I thought that it was of as they play fine on mtg computer and replies. I just thought it was because they were encoded in H265 and that my settings were bad.
I had not thought of using them as a weapon until know. Time to upload them and title them as a current hit movie. Lol
I guess you already forgot about I cloud?
I'm starting to thing that Google suffers from some form of corporate ADHD, by which I mean: they get distracted with other, "cooler", projects before the projects they create are working properly.
I'm saying this after discovering "Messenger", which I shall now use for SMS on my phone instead of Hangouts (which has a muted conversation notification bug that drives me crazy), which I used because the "Messaging" app that is built into the OS doesn't support muting and has performance issues with long threads (and it used to scroll to the bottom when a new message came in).
I also realised, after reading about the bug mentioned by TFS, that Google don't appear to have an "emergency patch" arrangement for Android. This in itself could be their Achilles' Heel should a bug that crashes or takes over all the phones running Android ever made become exploited wildly.
I can't even get my Android phone to play .mkvs, much less crash it. :(
Trend Micro reported to flaw in May, it said, but Google assigned it a low priority.
So, publishing it will presumably make them move the priority up? AFAIK, if the attacker could register the properly crafted MKV to play on start, you'd be in a bricked phone situation, factory reset, fixed done.
Harrison's Postulate - "For every action there is an equal and opposite criticism"
assholes p.s. mod me down -1
Thanks
how i can disable MMS. In the whole last 9 years when the phones i used supported MMS, i think i used the feature 3 times:
* one time for test
* two times to receive a train ticket (now they switched to internet+app)
I have no clue why i should use MMS. I use SMS a lot (since it works with all phones).
no need for this feature.