Post-Android 5.1.1 Update and Still Vulnerable?
TheS1R
Contributor - Level 2

I just completed the installation of Android 5.1.1 (Software Version: LMY47X.G920VVRU3BOG5) on my SAMSUNG Galaxy S6 edge -- the update appeared as available on my device late this morning. The Stagefright Detector utility from ZIMPERIUM still reports the device to be vulnerable with 2 out of 6 CVEs — it may be a false positive, but it is also possible that the patch was incomplete or not applied correctly.


https://play.google.com/store/apps/details?id=com.zimperium.stagefrightdetector&hl=en

Stagefright Post-5.1.1.png

0 Likes
Re: Post-Android 5.1.1 Update and Still Vulnerable?
GLW163
Contributor - Level 1

Several people have complained about this app. Try lookouts stage fright app and see what it tells you.

0 Likes
Re: Re: Post-Android 5.1.1 Update and Still Vulnerable?
TheS1R
Contributor - Level 2

I tried an updated version of ZIMPERIUM, Lookout, and two others -- Lookout was the only one of the three to report "no vulnerabilities" -- I am guessing that Lookout might not be checking for ALL of the applicable CVEs:

Screenshot_2015-08-14-17-40-16.png

Screenshot_2015-08-14-18-32-01.png

Screenshot_2015-08-14-18-29-43.png

Screenshot_2015-08-14-18-32-14.png

0 Likes
Re: Post-Android 5.1.1 Update and Still Vulnerable?
TheS1R
Contributor - Level 2
0 Likes
Re: Post-Android 5.1.1 Update and Still Vulnerable?
TheS1R
Contributor - Level 2

With its latest update, Lookout Stagefright Detector now also reports two vulnerabilities (i.e., both CVE-2015-1539 and CVE-2015-3827) but not the same ones as ZIMPERIUM (i.e., CVE-2015-3827 and CVE-2015-3864):

Screenshot_2015-08-19-18-07-46.png

0 Likes