HTC Android phone flaw fix not coming until next week for some
- 03 February, 2012 04:31
- Comments
Some users of HTC Android phones will have to wait until next week to get a fix for a problem that could leak credentials used to gain access to Wi-Fi networks, including corporate networks.
HTC is downplaying the severity of the problem and says most affected phones have already gotten the fix via updates and upgrades.
But it acknowledges users will have to manually load the software update and says those users should check back to its help page next week.
TIPS: Tricks for upgrading your Android phone
The flaw lies within the particular Android build used in certain models of HTC phones. It exposes Wi-Fi login credentials used as part of 802.1X network access control used on wireless networks.
A rogue application with rights to see that information and also with rights to access the Internet could steal the credentials and send them to attackers who might then use them to infiltrate a corporate network.
Google says no such rogue application has been found, according to a description of the flaw at the My War With Entropy blog by Bret Jordan. "Google has also done a code scan of every application currently in the Android Market and there are no applications currently exploiting this vulnerability," Jordan says.
For its part, HTC posted a paragraph on its help page about the flaw. "HTC has developed a fix for a small WiFi issue affecting some HTC phones. Most phones have received this fix already through regular updates and upgrades. However, some phones will need to have the fix manually loaded. Please check back next week for more information about this fix and a manual download if you need to update your phone," the posting says.
According to US-CERT, affected phones are:
• Desire HD (both "ace" and "spade" board revisions) - Versions FRG83D, GRI40
• Glacier - Version FRG83
• Droid Incredible - Version FRF91
• Thunderbolt 4G - Version FRG83D
• Sensation Z710e - Version GRI40
• Sensation 4G - Version GRI40
• Desire S - Version GRI40
• EVO 3D - Version GRI40
• EVO 4G - Version GRI40
Read more about anti-malware in Network World's Anti-malware section.
- Bookmark this page
- Share this article
- Got more on this story? Email TechWorld
- Follow TechWorld on twitter
- 8 useful Google Android resources
- HTC Android phones can leak Wi-Fi passwords
- HTC Help Center
- Tips and tricks for upgrading your Android phone
- Wireless Research Center - Network World
- US-CERT Vulnerability Note VU#763355 - 802.1X password exploit on many HTC Android devices
- Anti-malware Research Center - Network World
- The Top 5 Server Monitoring Battles—and How You Can Win Them
- Teleworking made simple—and secure—with desktop virtualisation technology
- Optimised License Management for the Datacenter
- HP 3PAR Utility Storage - Benefits Summary - Next-Generation Storage for Virtual and Cloud Data Centers
- Oracle Database 11g Product Family
-
CSIRO develops hands-free technology for mining repairs
-
Broadband Forum to improve IPTV performance with new spec
-
Amazon Web Services moves backups to cloud with new appliance
-
Callforfree.net.au offers free calls to 70 countries
-
Intel ponders solar-powered CPU tech in graphics, memory
-
MYOB Software for Dummies 6E Australian Edition
-
Computers for Seniors for Dummies, 2nd Edition
-
Office 2007 All-In-One Desk Reference for Dummies
-
Windows 7 for Dummies®
-
Windows 7 for Seniors for Dummies®
-
Microsoft Office
-
Office 2007 for Dummies
-
Windows 7 for Dummies® Dvd+book Bundle
-
Excel 2007 All-In-One Desk Reference for Dummies








Comments
Post new comment