Android OS image-handling bugs identified
8 March 2008 - 2:58
Core Security, who research exploits and loopholes in software releases, have identified eight different security issues in Google’s Android beta, including some that are blamed on the developer’s use of outdated and vulnerable open-source image libraries. The flaws could see a hacker take “complete control” of an Android-powered handset, including exploiting heap overflows and integer overflows, and Core Security demonstrated the issues with proof-of-concept code that worked successfully on the Android SDK emulator.
“Several vulnerabilities have been found in Android’s core libraries for processing graphic content in some of the most used image formats (PNG, GIF an BMP). While some of these vulnerabilities stem from the use of outdated and vulnerable open-source image processing libraries other were introduced by native Android code that use them or that implements new functionality” Core Security statement
1 Comment | Tags: Android, Android Community, Android SDK, Google Phone, SDK, software






Recently Google held three developer workshops - in London, Munich and Tel Aviv - to publicise accurate Android facts and demonstrate how to code on the platform; another such event will be held on the 23rd in Boston. 

