OGA || Stagefright Exploit Still Vulnerable? - Sprint Samsung Galaxy S6 Edge

So I've updated to the 5.1.1 Wicked One SS Rom which is based on OFE but supposedly has the OGA libs patched. I ran the Zimporium Stagefright Detector app available in google play and the device still shows vulnerable:
CVE-2015-1539
CVE-2015-3827
Anyone have any insight?
Let me know what your scans show. Tyia

pangolin.rollin said:
So I've updated to the 5.1.1 Wicked One SS Rom which is based on OFE but supposedly has the OGA libs patched. I ran the Zimporium Stagefright Detector app available in google play and the device still shows vulnerable:
CVE-2015-1539
CVE-2015-3827
Anyone have any insight?
Let me know what your scans show. Tyia
Click to expand...
Click to collapse
Not completely fixed. Not even on stock OGA. Sure they'll be another update sooner or later. This has been around for years, nothing new

Related

[ROM]RUU_Bravo_Froyo_HTC_WWE_2.29.405.5_Radio_32.49.00. 32U_5.11.05.27_release

Here new RUU for Bravo
http://www.filefactory.com/file/b4a...9.00.32U_5.11.05.27_release_159811_signed.exe
Enjoy!
Hope someone could make a flashable zip file...
Stock ROM, rooted, bash, busybox, init.d support.
Updated system applications to the latest (apart from Facebook as I forgot )
http://www.multiupload.com/C81QMCS31N
Uses the same Kernel as 2.29.405.2 - can't really see any changes
The kernel is identical. The system image is not, but almost. A quick look shows some differences, e.g. HTCSetupWizard, Vending apps, various framework files.
Is it different from 2.29.405.2 or has worthwhile to update.
was wondering the same worth the update?
i have installed this update, some applications are updated like market version 1.82 to 2.09 and some more.
No other applications are updated.
Here new RUU for Bravo
http://www.filefactory.com/file/b4a4...811_signed.exe
Enjoy!
Transfer to a not swing
beinadvance said:
Here new RUU for Bravo
http://www.filefactory.com/file/b4a4...811_signed.exe
Enjoy!
Transfer to a not swing
Click to expand...
Click to collapse
Link doesn't work - what version is it?
Mekrel said:
Link doesn't work - what version is it?
Click to expand...
Click to collapse
Same one as post 1, only broken link.
MichelN said:
Same one as post 1, only broken link.
Click to expand...
Click to collapse
Oh yeah hehe, I see what's happened now.
Sent from my HTC Desire using XDA App
Mirrors
Took me half a day to download this, if not even more, cause their servers were to busy for non premium users.
So I've uploaded it to multiupload.
http://www.multiupload.com/LEJCW182AH
dou you have PB99IMG version. I want to install SD card ?
ramis7 said:
i have installed this update, some applications are updated like market version 1.82 to 2.09 and some more.
Click to expand...
Click to collapse
I have 2.29.405.2 and Market Version 2.12
If thats the only change then the update is not worth flashing. You get a newer market version by ... just doing nothing.
Mr. Frost said:
I have 2.29.405.2 and Market Version 2.12
If thats the only change then the update is not worth flashing. You get a newer market version by ... just doing nothing.
Click to expand...
Click to collapse
I have 2.29.405.2 and I am running Android Market 2.2.7 (did nothing for it, came silently some days ago). And yes it's the new one with the new design.
I don't have the new market (with the new design) but still a newer version than in this update.
But there has to be something more. Why should HTC update their ROM just because of a new version of the market? They don't update when a new version of flash is available, or maps .... or anything else. You get the new versio anyway. Doesn't make sense to me.
Mr. Frost said:
I don't have the new market (with the new design) but still a newer version than in this update.
But there has to be something more. Why should HTC update their ROM just because of a new version of the market? They don't update when a new version of flash is available, or maps .... or anything else. You get the new versio anyway. Doesn't make sense to me.
Click to expand...
Click to collapse
It is a slightly revised version of the same build. Almost everything is *exactly* the same. This release may never be made officially available.
do you have to wipe data to flash this
Sent from my HTC Desire using XDA App
czech/slovak lenguage
hi,
wanna ask if i flash to this stock official rom will i get the support languages like czech(slovakia) and so on for europe users?
my mobile brand is Orange slovakia
thx and regards

MD3 OTA officially pulled per Samsung Open Source Release Center

[SAMSUNG OSRC COMMENTS DELIVERY NOTIFICATION]
♦ classification : mobile_phone ♦
♦ model name : SCH-I535_NA_JB ♦
Hello,
MD3 FOTA service was stopped recently because the sw version has data issue.
So we'll release the new binary fixed the issue soon.
And the opensource for new version will be posted.
Thanks.
Click to expand...
Click to collapse
Got this email a few minutes ago. Guess this explains why the source request was taking so long.
well good to know at least there on top of things
just now how long till it's fixed
LLStarks said:
Got this email a few minutes ago. Guess this explains why the source request was taking so long.
Click to expand...
Click to collapse
I was just checking out that site...so the link it has for MB1 for SCH-i535 is the full MB1 OTA you can flash basically?
No, you can't flash anything from that site.
Aaaaaaand this is why we want an unlocked bootloader, Verizon.
Sent from my SCH-I535 using Tapatalk 4 Beta
NinCaptain said:
well good to know at least there on top of things
just now how long till it's fixed
Click to expand...
Click to collapse
One day for Samsung to fix and 3 months for Verizon to test and approve.
LLStarks said:
Guess this explains why the source request was taking so long.
Click to expand...
Click to collapse
Source for what ? I'm new to Samsung devices, but not Android, and they only have to release source for the kernel. This recent update didn't include a new kernel, did it ? If Samsung uses other open-source code, I didn't know.
hallstevenson said:
Source for what ? I'm new to Samsung devices, but not Android, and they only have to release source for the kernel. This recent update didn't include a new kernel, did it ? If Samsung uses other open-source code, I didn't know.
Click to expand...
Click to collapse
I'm not sure what the OP is talking about . The radio/modem is not open source, its Verizon proprietary. So unless the bug is in the Samsung portion open source does not apply
hallstevenson said:
Source for what ? I'm new to Samsung devices, but not Android, and they only have to release source for the kernel. This recent update didn't include a new kernel, did it ? If Samsung uses other open-source code, I didn't know.
Click to expand...
Click to collapse
Kernel source, there's a new kernel with each update. At least there is when referencing the date it was compiled. I won't claim to say I read code/source but there's definitely a few adjustments between one compiled OTA kernel and the next.
DigitalMD said:
I'm not sure what the OP is talking about . The radio/modem is not open source, its Verizon proprietary. So unless the bug is in the Samsung portion open source does not apply
Click to expand...
Click to collapse
The modem being proprietary isn't the main concern. If what OP has posted is true, Samsung is just withholding VRBMD3 kernel source to push another OTA after which they'll provide kernel source for that newer OTA.
Llstarks just wants source and there's nothing wrong with that. Just means we have to wait a little longer is all.
Sent from my SCH-I535 using Tapatalk 4 Beta
Well, we wanted the source so we could figure out what was going on between the camera blob and the trust zone partition.
Camera wasn't loading with a MD3 tz.

[Q] Beanstalk OTA Update

I have been a user of Cyanogenmod on my Verizon Galaxy S3 for a while now. I'm what most would call a newbie as far as android tech flash custom rom stuff. But I can get around...
My question is I just flashed Beanstalk and everything seems good so far. Loveing 4.4 (why I switched from Cyanogenmod) I get an OTA notification about a new version of Beanstalk but the numbers don't seem to be NEWER.
Current Beanstalk: 4.4.215-20140117-d2vzw
Update Version: 4.3.1009-20131016-d2vzw
Doesn't make sense to me, is there something wrong with the OTA app, or are they falling back to a previous version for some reason...anyone with info or help. Thanks!
I noticed the same thing. I believe the OTA updater may be broken or not updated. You have the latest build.
I get the same thing here
Been getting this since installing beanstalk that included the beanstalk OTA app....love the idea of it but it looks like the OTA app is broken or beanstalk is reporting itself as the wrong version.
I am running the most current 4.4.285 i believe but yet i get update notifications that new versions are available.
The "new" versions message i get is:
2 updates available for download
Beanstalk-4.3.1015-20131227-d2att.zip
Beanstalk-4.3.1009-20131015-d2att.zip
anyone figure this out as i am getting these older versions but not an actual new versions (and newer did exist while getting this message)?
When I was using beanstalk it was the same issue it would warn me of a lower version update. I don't know why it seems like to do that but just ignore it
Sent from my SCH-I535 using Xparent ICS Tapatalk 2
ShapesBlue said:
When I was using beanstalk it was the same issue it would warn me of a lower version update. I don't know why it seems like to do that but just ignore it
Click to expand...
Click to collapse
Me too. The only AOSP ROM I've ever used that actually had a working OTA updater was C-ROM.

should i update my s6 to 5.1.1?

i didnt get the ota update but when i connected to Smart Switch it shows the 5.1.1 update..... what do i do?????
update it or no
Might as well update, it's batter than 5.0.2 was IMO
abi_sam said:
i didnt get the ota update but when i connected to Smart Switch it shows the 5.1.1 update..... what do i do?????
update it or no
Click to expand...
Click to collapse
5.1.1 adds RAW image support. It also has a flurry of bug fixes and security patches. As long as you don't care about root I would say go for it.
Snowby123 said:
5.1.1 adds RAW image support. It also has a flurry of bug fixes and security patches. As long as you don't care about root I would say go for it.
Click to expand...
Click to collapse
i read some where that it dosent support RAW image.
abi_sam said:
i read some where that it dosent support RAW image.
Click to expand...
Click to collapse
When Samsung announced the 5.1.1 update, camera improve Mrs were the biggest part of the update. I know that many users have said the camera improvements are there. I actually have seen photo samples and they look pretty good.
abi_sam said:
i didnt get the ota update but when i connected to Smart Switch it shows the 5.1.1 update..... what do i do?????
update it or no
Click to expand...
Click to collapse
Don't update! The battery life of the preinstalled stock ROM is a little better as is the case in almost all smartphones.
I wished I didn't update, but the thing downloaded the update automatically
Nothing wrong with 5.1, but I find 5.0 battery life is better!
Fullmetal Jun said:
Don't update! The battery life of the preinstalled stock ROM is a little better as is the case in almost all smartphones.
I wished I didn't update, but the thing downloaded the update automatically
Nothing wrong with 5.1, but I find 5.0 battery life is better!
Click to expand...
Click to collapse
I find 5.1 battery life to be not too bad.
If you're willing to forgo all the patches, updates and improved RAM just for the sake of battery life, be my guest.
Yeah definitely update the phone. When I first got it the phone was very laggy compared to my m8 but with the update it's gotten better. Don't get me wrong, it still has its lags here and there but not nearly as much as before
Sent from my SM-G920T using XDA Free mobile app
Holding back on installing the update doesn't make sense to me.
The update includes various features, improvements, tweaks and fixes. Why wouldn't you apply it?
Sent from my SM-G925I using Tapatalk
You can root 5.1.1 but some roms aren't updated to 5.1.1 so you won't be able to flash them due to the new bootloader also once you go to 5.1.1 there is no going back to 5.0.2 due to the new bootloader so I would just use a 5.1.1 ROM unless that has WiFi issues for you then just update.

[Question] Is there any way to intall/update only security patches?

I want to stay on MM (6.0.1). I am using a custom Rom (Alexis Rom) which is no longer updated.
What I want is to update only Android security patches.
Is there anyway to do this?
I am rooted and running a custom TWRP if it helps at all....
Thanks :fingers-crossed:
zapahacks said:
I want to stay on MM (6.0.1). I am using a custom Rom (Alexis Rom) which is no longer updated.
What I want is to update only Android security patches.
Is there anyway to do this?
I am rooted and running a custom TWRP if it helps at all....
Thanks :fingers-crossed:
Click to expand...
Click to collapse
At this point in time, no. The way security patches are incorporated requires them to be baked into firmware from scratch probably stops the ability to incorporate them on the fly. I don't think reapply able patches has been achieved for any android device.
sofir786 said:
At this point in time, no. The way security patches are incorporated requires them to be baked into firmware from scratch probably stops the ability to incorporate them on the fly. I don't think reapply able patches has been achieved for any android device.
Click to expand...
Click to collapse
Thanks. Hopefully in the future we could flash them as an OTA update.

Categories

Resources