MS509团队获三星官方致谢
2016-11-9 14:34:50 Author: mp.weixin.qq.com(查看原文) 阅读量:0 收藏

近日,三星手机公司发布了2016年11月份的安全公告[1],对MS509团队发现的一中危漏洞予以致谢。

漏洞详情如下:

SVE-2016-7044: system_server crash, DoS (AntService)

Severity: Medium
Affected versions: KK(4.4), L(5.0/5.1), M(6.0)
Reported on: September 6, 2016
Disclosure status: Privately disclosed.
The system services “AntService” doesn’t have proper access control and exception handling. And it allows attackers to use system API of “AntService” and cause rebooting of device by force-crashing the service.
The patch restricts unauthorized access to the “AntService” and filters out improper cases which may cause crash。

[1] http://security.samsungmobile.com/smrupdate.html#SMR-NOV-2016


文章来源: https://mp.weixin.qq.com/s?__biz=MzAwODgxNTA2NA==&mid=2650935225&idx=1&sn=1766d0e3182d4fdaac6fee8896ace345&chksm=809f870eb7e80e1813e8a76cf3108ebb81c22384f7de39b3561ccea50ab64ec9b62cd80bcb02&scene=58&subscene=0#rd
如有侵权请联系:admin#unsafe.sh