meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Thursday, February 7th 2019

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 6 February 2019

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. PNG Android Vulnerability; Skia Graphics Library Vuln; Google Chrome Password Check;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Thursday, February 7, 2019 edition of the Sandsenet Storm Center's Stormcast.

0:07.8

My name is Johannes Ulrich, and I'm recording from Jacksonville, Florida.

0:13.8

Google released its monthly update for Android, and among the vulnerabilities being addressed here,

0:19.9

there are three that sort of stick out

0:21.6

and Google actually also points them out in its advisory, CVE 2019, 1986, 87 and 88. These vulnerabilities

0:32.9

affect what they are calling the framework, the basic libraries that are coming with Android, and

0:39.3

particularly how PNGs are being displayed. Apparently, due to these vulnerabilities,

0:46.3

it is possible to execute arbitrary code on an Android phone if you are viewing a malicious PNG.

0:55.5

Since this is the basic PNG rendering library, this affects any software on Android that

1:02.4

does display PNGs.

1:04.4

So this could be exploited via SMS, via email, and via a web browser. So as usual, make sure that you upgrade quickly.

1:14.7

This affects Android 7,8, and 9. And talking about vulnerabilities in graphics libraries, Google's

1:25.2

Project Zero has a real neat blog post by Ivan Frederick,

1:28.9

where he goes into quite a bit of details in vulnerability that was recently discovered in the

1:35.5

Skiya graphics library. Now, Skiya, you may not have heard of it before. I haven't had

1:41.5

heard of it, but apparently this, the library being used by browsers,

1:46.0

for example, Chrome, Firefox, also Android uses this library.

1:50.0

So vulnerability in the Skiah library certainly could have quite substantial impact.

1:56.0

Now the neat thing about the blog post is that it really goes in depth into some of the algorithms being used

2:02.6

to draw different polygons and what kind of memory corruption issues can show up if this is not done right.

2:11.6

So great blog post but sadly a little bit too complex and too much to really do justice here in the podcast.

2:19.0

So I'll just refer you to the show notes for details.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.