Email this article   Print article 

Google Fixes Two Android DoS Bugs

By Stefanie Hoffman, CRN
October 12, 2009    8:14 PM ET

Google released patches repairing two security flaws in its Android mobile operating system, which enabled hackers to launch denial of service attacks on users' smartphones.

The flaws, made public by the Open Source Computer Emergency Response Team (oCERT), affected Android version 1.5.

One of the most serious security vulnerabilities occurs in the way Android handles SMS messages. Hackers can create malformed SMS message from a badly formatted WAP Push message, which, in turn, could trigger a mobile phone to disconnect from the cellular network, oCERT reports in a security advisory.

The second patch Google released addressed numerous security issues in the Android Dalvik API, including a DoS vulnerability that leads to a system process restart.

Hackers could launch a DoS attack by creating a malicious application, which would then be sent to the user's mobile device, typically through some kind of social engineering scheme. The malware would subsequently trigger the affected API function and cause a system restart once users opened and downloaded the application.

"The same condition could occur if a developer unintentionally places the vulnerable function in a place where the execution path leads to that function call. Triggering this bug is considered a DoS condition," oCERT said in its advisory.

The Google Android OS is primarily used on consumer smartphones, but is starting to gain ground in the enterprise space.

Android gained some steam -- and credibility -- after numerous cell phone makers and wireless carriers recently announced plans to launch handsets built around the open source platform.

Altogether, the Google Android OS is the driving force behind nine devices with 32 carriers in 26 countries, according to The Wall Street Journal. While the Android has made clear strides on the consumer front, its steady emergence as a viable enterprise platform has also made it an increasingly attractive target for hackers.


Email this article   Print article 

More Security

Recent Articles

Cybersecurity Experts: What They Know Could Scare You

A recent report based on interviews with security experts in government, business and academia finds more than half in agreement that a worldwide arms race is taking place in cyberspace.

10 Security Predictions For 2012

CRN looks into its crystal ball and sees Android, hactivisim and cyber-espionage as some of the top 10 security threats in 2012.

10 Biggest Security Breaches Of 2011

The Top 10 Security Breaches of 2011 show hackers were relentless in their pursuit of profit, compromising computer systems of universities, video-game makers and the largest banks.

  More Slide Shows




Related Videos
Loading...