Arjen Vogel retweetledi

Over one year we collected Android patch data from phone firmwares. Today we published an analysis detailing patch coverage and time-to-patch for the different vendors: srlabs.de/bites/android-… (1/3)
English
Arjen Vogel
171 posts

@arjenvogel
Views are my own, retweets are no endorsement



We found multiple attacks on RCS, ranging from remote text message intercept to local MitM. Vulnerabilities lie in misconfigured deployments and the official Android messaging app. We present our attacks and how to fix them @BlackHatEvents and @deepsec. srlabs.de/bites/rcs-hack…

CVE-2019-18217 ProFTPD before 1.3.6b and 1.3.7rc before 1.3.7rc2 allows remote unauthenticated denial-of-service due to incorrect handling of overly long commands because main.c in a child process enters an infinite loop. cve.mitre.org/cgi-bin/cvenam…
















