Advertisement
Promo

Security threats Toolkit

Google offers details on 'reboot' bug, Android fixes

Stephen Shankland CNET News

Published: 12 Nov 2008 09:37 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Google has begun releasing details about the vulnerabilities it patched in two updates to Google's Android operating system software in the T-Mobile G1 smartphone.

The company had acknowledged some of the work earlier, but it has not posted an official comment about the vulnerabilities. However, Rich Cannings of the Android security team has shared details about the RC29 and RC30 updates that T-Mobile began distributing to G1 customers at least as early as 1 November and 9 November, respectively.

Google had acknowledged the RC29 patch for the G1 fixed a browser vulnerability that could have let an attacker use malicious code on a website to take over the browser. The severity of such issues is limited by Android's security design, which walls off applications into separate compartments to limit an attacker's power. But Cannings said the patch also fixed two other issues.

The Android browser is based on the open-source WebKit engine for converting HTML instructions into a web page, and RC29 brought Android up to date with two patches that had been released but that Google had missed. One of them is a universal cross-site scripting problem that could give an attacker control of the browser, Canning said.

RC29 also fixed a problem that could let someone bypass Android's locking mechanism by booting the phone into safe mode.

Google plans to publish fuller details on its Android Security Announcements group soon, Cannings said, but the company waits until the patches have been offered to all users before disclosing full details.

RC30 and the root console bug
RC30, which came about a week later, fixed an unusual 'root-console' problem in Android in which text people typed — while composing email messages or searching contacts, for example — could be executed as Linux commands with the highest-level privileges. One user found it by typing the word 'reboot' in a text message.

The problem was that Google left in a feature that let programmers execute commands with a remote device attached over a serial port, but when there was no such device attached, the phone just used input from the keyboard.

Linux and Unix users are advised to use their systems with 'root' privileges reserved only for administrators, but Android was giving anybody that privilege. The problem was lessened because many characters used in Linux commands, such as hyphens, tildes and slashes, weren't available, but it was still a big problem, Cannings said.

"We tried really hard to secure Android. This is definitely a big bug," he said. "The reason why we consider it a large security issue is because root access on the device breaks our application sandbox."

On the flip side, though, it would have been hard to use: "The barrier is very high to exploit this... It requires a challenger to exploit users," he said. "For example, an attacker might have to convince a user to install a game with keyboard movement commands that typed out 'telnetd' to launch the phone's telnet application to open the phone up to remote control."

RC30 also fixes two WebKit problems that Apple — which also uses the software in its Safari Browser — reported to Google, Cannings said. First is a buffer overrun issue relating to JavaScript style sheets that could let an attacker gain control over the browser by putting malicious code on a website. Second is a problem that could let people read what's in the phone's memory, potentially gaining access to website cookies and thereby gaining online privileges. "If you're logged into a bank at that time, [an attacker] could steal your banking cookies," Cannings said.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
3 out of 5 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:






Video icon

Video

Sentry Posts Blog

Campaigners criticise '£10bn NHS IT ov...

The National Health Service's flagship IT project has been criticised by a tax campaign group for running billions of pounds over budget. The NHS National Programme for IT (NPfIT)... More

1 comment

Climate research centre compromised

One of the UK's leading climate change research centres has had a security breach. The Climate Research Unit at the University of East Anglia (UEA) suffered a compromise of information,... More

1 comment

Government web-monitoring plans on hol...

Government plans to compel ISPs to process and store details of all web communications have been put on hold until after the next election. The Home Office told ZDNet UK on Wednesday... More

1 comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters