Vulnerabilities found in Sony Ericsson phones

Several mobile phones produced by Sony Ericsson are vulnerable to denial-of-service attacks, two security companies reported this week.

The flaw is found in four models of Sony Ericsson phones and comes from an error in their Bluetooth service, according to the French Security Incident Response Team, or FrSIRT.

The Bluetooth "fails to properly handle malformed L2CAP (Logical Link Control and Adaptation Layer Protocol)," FrSIRT, a France-based security company, said in an advisory posted on its Web site.

Danish security firm Secunia reported the same flaw, and both companies have rated the potential security risk as low. Thomas Kristensen, Secunia's chief technology officer, said that someone intent on knocking out one of the four Sony Ericsson phones, which includes the K600i and T68i, would need only to get within 50 feet (15.24 metres) while carrying a handheld device configured to send the malicious code via Bluetooth. The code would crash the phone.

"I don't think the phone's user would even know the attack occurred until they tried to use their phone again," Kristensen said.

The good news is that damage would be minimal. Once the phone was turned off and restarted, it would function normally again, Kristensen said.

"Sony Ericsson believes that the possibilities to exploit the Sony Ericsson products mentioned are very limited," company spokeswoman Cherie Gary said in an e-mail. "However, if you are concerned, you can help prevent access to the phone by switching off the 'discoverable' mode in the Bluetooth settings of the phone. This makes the phone invisible to others and thereby minimises the risk of being accessed."

Gary said that she is waiting to learn more details from Sony Ericsson engineers in Sweden who would have more information.

While this specific vulnerability may be low risk, Kristensen cautioned that these kinds of vulnerabilities in mobile phones are a growing concern in the security community. Conceivably, hackers could pilfer information from mobile phones one day if the handsets aren't provided with the right security measures.

So far, mobile users have only had to worry about mobile phone viruses, which are still very rare. In October, Nokia tapped Symantec to help secure its mobile phones from viruses that target certain kinds of handsets. Experts don't expect a fast-spreading mobile phone virus to strike for two more years.

Like this article? Click below to send it to your mobile for free!

Advertisement

Talkback 0 comments


Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Alex Serpo Is green IT a marketing fad?
    It seems that green IT has dropped off the radar, with other technology issues moving to the fore. But was green IT ever a real technology movement, or was it just a marketing fad?
  • Array Gutless studios have the wrong target
    I have one word for the Australian Federation Against Copyright Theft (AFACT). Gutless.
  • Array NBN needs workers on board
    Without consensus on labour issues, the eventual winner of the NBN may end up as little more than a lame duck and a cashed-up symbol of the conflict between the desire for progress and the lack of mechanisms to deliver it.
  • More blogs »

Tags

Back to top

Featured