Google Patches More Stagefright Vulnerabilities In Android (threatpost.com)
msm1267 writes: The Stagefright vulnerabilities are the gifts that keep on giving. Months after the potentially devastating security flaws in the mobile OS were publicly disclosed, Google continues to send out patches addressing vulnerabilities related to the initial reports. Today's monthly Android security bulletin includes a fix for another flaw in the Stagefright media playback engine, one in libutils where the Stagefright 2.0 vulnerabilities were found, and two in Android Mediaserver where all the vulnerable code runs. The over-the-air update was released today to Google's Nexus devices and will be added to the Android Open Source Project (AOSP) repository in the next two days; Google partners including Samsung were provided the patches on Oct. 5, Google said, adding that the vulnerabilities are patched in Build LMY48X or later, or in Android Marshmallow with a patch level of Nov. 1.
And how many months if EVER will Verizon and carriers send out these updates? I'm still waiting for the last 3 patches that they haven't done shit about.
Google used LUDDITE software called Stagefright, which is why Android is so insecure! If they used APP frameworks like AppMedia and AppApp, it would be 100% secure, because only apps can app apps!
Apps!
Is this the same patch Motorola release the other week for Moto X 2014 devices? It said it was a fix for some Stagefright vulnerabilities
Google programmers should read this book.
They can do much better at avoiding bugs than they are now.
"First they came for the slanderers and i said nothing."
Here's another set of Android vulns that I believe were not mentioned here on Slashdot earlier.....
"First they came for the slanderers and i said nothing."
I have a 2.5 year old phone that I otherwise love and while it's EOL, I still use it extensively.
The idea that a phone can be not even 3 years old and not have any hope of getting updates is something I balk STRONGLY at.
I have no problem with your religion until you decide it's reason to deprive others of the truth.
For the carriers to actually send out updates for devices that are older than 3 months.
Not sure you are following the analogy, because the original complaint is that you need the carriers permission to install an update from Google.
Meanwhile Apple is supporting devices around four years old with updates, no matter what carrier you have.
"There is more worth loving than we have strength to love." - Brian Jay Stanley
As I wrote a couple of months ago, if you check the Factory Images for Nexus Devices you'll see that "nakasi" for Nexus 7 (Wi-Fi) remains at LMY47V, which was released before the libstagefright vulnerabilities were (mostly) patched.
This is an exceptionally popular device. I bought the newly released 32GB version for Christmas 2012. Google doesn't even care about patching its own-branded devices sold internationally less than three years ago.
So now I have to buy a new phone? Why don't they just make the damn things disintegrate (biodegradable) after two years? Bastards!
“He’s not deformed, he’s just drunk!”
Google should admit there is a problem in Android's model of getting updates and do something about it.
It is not just code.
If they don't care because Android is doing well in terms of market share etc, they should read comments & stories about Nokia Symbian. Developers, users, authors were telling them everything which were wrong and they were laughing at them showing their massive marketshare. Now, their own Google Keyboard didn't autocomplete Symbian, it is that irrelevant.
Comment removed based on user account deletion
Nothing penetrates Linux android. I read this on /. all the time. Everyone knows java/dalvik is "the 'bestest' safest language" that makes bug free code too! Now, I am going to read the article - wtf? Oops. Guess all of /. is at fault for all your years of linux is secure no other OS is. I blame you fucking liars for feeding me that shit.
The patch to the older OS is the new OS. Not sure how difficult that is to understand.