<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[PNG vulnerability]]></title><description><![CDATA[<p dir="auto">Hi,</p>
<p dir="auto">On Android a important security hole was be found making PNG dangerous to read (<a href="https://thehackernews.com/2019/02/hack-android-with-image.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2019/02/hack-android-with-image.html</a>).<br />
The vulnerable lib seems to be skia (function SkPngCodec).</p>
<p dir="auto">This lib is present on ubPorts according presence of this files are present :<br />
/var/lib/lxc/android/rootfs/system/lib/libskia.so<br />
/android/system/lib/libskia.so</p>
<p dir="auto">Is it possible to secure it ?<br />
Is disabling "Enable MMS message" option in Message app avoid risk of beeing hacked with MMS ?</p>
<p dir="auto">Thanks for promoting (really) free OS.</p>
]]></description><link>https://forums.ubports.com/topic/2354/png-vulnerability</link><generator>RSS for Node</generator><lastBuildDate>Mon, 08 Jun 2026 10:44:13 GMT</lastBuildDate><atom:link href="https://forums.ubports.com/topic/2354.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 08 Feb 2019 18:41:16 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to PNG vulnerability on Mon, 11 Feb 2019 16:23:58 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/dobey" aria-label="Profile: dobey">@<bdi>dobey</bdi></a> ah, I see... thanks for clearing up.</p>
]]></description><link>https://forums.ubports.com/post/17370</link><guid isPermaLink="true">https://forums.ubports.com/post/17370</guid><dc:creator><![CDATA[jezek]]></dc:creator><pubDate>Mon, 11 Feb 2019 16:23:58 GMT</pubDate></item><item><title><![CDATA[Reply to PNG vulnerability on Mon, 11 Feb 2019 14:44:54 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/jezek" aria-label="Profile: jezek">@<bdi>jezek</bdi></a> No, that has nothing to do with the Android container part.</p>
]]></description><link>https://forums.ubports.com/post/17365</link><guid isPermaLink="true">https://forums.ubports.com/post/17365</guid><dc:creator><![CDATA[dobey]]></dc:creator><pubDate>Mon, 11 Feb 2019 14:44:54 GMT</pubDate></item><item><title><![CDATA[Reply to PNG vulnerability on Sat, 09 Feb 2019 22:18:17 GMT]]></title><description><![CDATA[<p dir="auto">No image data is passed through that part of the container, so you are not at risk using UT. Idk why this dependency is in, but probably it could be removed from the lxc container.<br />
BR</p>
]]></description><link>https://forums.ubports.com/post/17316</link><guid isPermaLink="true">https://forums.ubports.com/post/17316</guid><dc:creator><![CDATA[flohack]]></dc:creator><pubDate>Sat, 09 Feb 2019 22:18:17 GMT</pubDate></item><item><title><![CDATA[Reply to PNG vulnerability on Mon, 11 Feb 2019 16:30:38 GMT]]></title><description><![CDATA[<p dir="auto"><strong>EDIT:</strong> As I was informed by <a class="plugin-mentions-user plugin-mentions-a" href="/user/dobey" aria-label="Profile: dobey">@<bdi>dobey</bdi></a>:</p>
<blockquote>
<p dir="auto">No, that has nothing to do with the Android container part.</p>
</blockquote>
<p dir="auto">So, anything, below this is a bad advice and is not working.<br />
<strong>END OF EDIT</strong></p>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/raphastronome" aria-label="Profile: RaphAstronome">@<bdi>RaphAstronome</bdi></a> said in <a href="/post/17273">PNG vulnerability</a>:</p>
<blockquote>
<p dir="auto">I tried to rename it but not possible because readonly FS :</p>
</blockquote>
<p dir="auto">to unlock read this:<br />
<a href="https://ubports.com/de_DE/blog/ubports-blog-1/post/terminal-chapter-3-124" target="_blank" rel="noopener noreferrer nofollow ugc">https://ubports.com/de_DE/blog/ubports-blog-1/post/terminal-chapter-3-124</a></p>
<p dir="auto">tldr;</p>
<pre><code class="language-bash">$ sudo mount -o remount,rw /
</code></pre>
]]></description><link>https://forums.ubports.com/post/17306</link><guid isPermaLink="true">https://forums.ubports.com/post/17306</guid><dc:creator><![CDATA[jezek]]></dc:creator><pubDate>Mon, 11 Feb 2019 16:30:38 GMT</pubDate></item><item><title><![CDATA[Reply to PNG vulnerability on Fri, 08 Feb 2019 21:27:22 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/raphastronome" aria-label="Profile: RaphAstronome">@<bdi>RaphAstronome</bdi></a> said in <a href="/post/17273">PNG vulnerability</a>:</p>
<blockquote>
<p dir="auto">A way to remove it ?</p>
</blockquote>
<p dir="auto">The image would need to be re-built without the file, and I don't know if that's doable. However, as I said, I'm pretty certain it's not used.</p>
<p dir="auto">Also, it's not clear that the vulnerability affects the version of Android which currently supported devices is built upon. So far, everything I can find about this specific vulnerability, is saying Android 7.0-9 only. It would help to have accurate information, rather than vague statements.</p>
]]></description><link>https://forums.ubports.com/post/17279</link><guid isPermaLink="true">https://forums.ubports.com/post/17279</guid><dc:creator><![CDATA[dobey]]></dc:creator><pubDate>Fri, 08 Feb 2019 21:27:22 GMT</pubDate></item><item><title><![CDATA[Reply to PNG vulnerability on Fri, 08 Feb 2019 19:17:33 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/dobey" aria-label="Profile: dobey">@<bdi>dobey</bdi></a> said in <a href="/post/17269">PNG vulnerability</a>:</p>
<blockquote>
<p dir="auto">Unless Google releases an update for older Android (4.4, 5.1)</p>
</blockquote>
<p dir="auto">Ok, this will never happens <img src="https://forums.ubports.com/assets/plugins/nodebb-plugin-emoji/emoji/android/1f61e.png?v=aee68f5cf05" class="not-responsive emoji emoji-android emoji--disappointed" style="height:23px;width:auto;vertical-align:middle" title=":disappointed:" alt="😞" /> .</p>
<p dir="auto">I tried to rename it but not possible because readonly FS :</p>
<pre><code>phablet@ubuntu-phablet:/$ sudo -s
[sudo] password for phablet: 
root@ubuntu-phablet:/# cd
root@ubuntu-phablet:~# mv /android/system/lib/libskia.so /android/system/lib/libskia.so.avoid
mv: cannot move '/android/system/lib/libskia.so' to '/android/system/lib/libskia.so.avoid': Read-only file system
root@ubuntu-phablet:~# mv /var/lib/lxc/android/rootfs/system/lib/libskia.so /var/lib/lxc/android/rootfs/system/lib/libskia.so.avoid
mv: cannot move '/var/lib/lxc/android/rootfs/system/lib/libskia.so' to '/var/lib/lxc/android/rootfs/system/lib/libskia.so.avoid': Read-only file system
</code></pre>
<p dir="auto">A way to remove it ?</p>
<p dir="auto">Thanks,</p>
]]></description><link>https://forums.ubports.com/post/17273</link><guid isPermaLink="true">https://forums.ubports.com/post/17273</guid><dc:creator><![CDATA[RaphAstronome]]></dc:creator><pubDate>Fri, 08 Feb 2019 19:17:33 GMT</pubDate></item><item><title><![CDATA[Reply to PNG vulnerability on Fri, 08 Feb 2019 18:47:57 GMT]]></title><description><![CDATA[<p dir="auto">Unless Google releases an update for older Android (4.4, 5.1), it's not likely that file will be updated in UBports. However, I don't think it is used either (though something in the android container may link to it and require its presence).</p>
<p dir="auto">MMS handling in UT does not use that library.</p>
]]></description><link>https://forums.ubports.com/post/17269</link><guid isPermaLink="true">https://forums.ubports.com/post/17269</guid><dc:creator><![CDATA[dobey]]></dc:creator><pubDate>Fri, 08 Feb 2019 18:47:57 GMT</pubDate></item></channel></rss>