Commentary

Android SDK Not Secure, Vulnerable To Attack

According to researchers, certain open-source image processing libraries in Google's Android SDK are outdated and can be attacked by hackers. A total of eight vulnerabilities were found by Core Security. Core showed that the weaknesses can result in hackers taking complete control of Android handsets.

According to researchers, certain open-source image processing libraries in Google's Android SDK are outdated and can be attacked by hackers. A total of eight vulnerabilities were found by Core Security. Core showed that the weaknesses can result in hackers taking complete control of Android handsets.Core issued an advisory yesterday, and said, "Several vulnerabilities have been found in Android's core libraries for processing graphic content in some of the most used image formats (PNG, GIF an BMP). While some of these vulnerabilities stem from the use of outdated and vulnerable open-source image processing libraries, others were introduced by native Android code that use them or that implements new functionality."

Losing total control to hackers is a worst-case scenario. But I don't think there's any cause for alarm.


More Internet Insights

White Papers

More >>

Reports

More >>

Webcasts

More >>

Keep in mind that the Android platform is currently available to developers in a beta release. Even though some hardware vendors have shown off working prototypes using early versions of the code, the final version of Android won't be available until later this year. Neither will handsets. The development community will likely find more weaknesses and bugs in Android before the final build is created.

According to the official Android Developers Blog, Google was aware of the problem, and issued a fix in the latest build of the platform (which was released last month).

Reports like this are going to continue to bubble to the surface as developers dig their fingers into the code. Creating a mobile platform takes time. Finding and fixing bugs is part of the process. The final version of Android will have all the ingenuity and skills of the Linux developer community behind it. That is sure to include rock-solid security.


Related Reading




Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

InformationWeek encourages readers to engage in spirited, healthy debate, including taking us to task. However, InformationWeek moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. InformationWeek further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
T-Shirt Giveaway T-Shirt Giveaway: Each week we're selecting one great comment from our readers. The author of the comment will receive an InformaitonWeek Community t-shirt. So get posting!
Subscribe to RSS

Resource Links