Register Guidelines E-Books Today's Posts Search

Go Back   MobileRead Forums > E-Book Readers > Android Devices > enTourage eDGe

Notices

Reply
 
Thread Tools Search this Thread
Old 07-24-2011, 03:22 PM   #1
DoghouseReilley
Junior Member
DoghouseReilley began at the beginning.
 
DoghouseReilley's Avatar
 
Posts: 7
Karma: 10
Join Date: Jul 2011
Location: KMC, De
Device: Entourage PocketEdge; Motorola Droid2
Exploit-CVE-2010-2738 in Ermine updates?

TL,DR: Multiple versions of the update.zip for the Pocket Edge are being flagged by McAfee Stinger as having a virus.
Well met, strangers. I bought an enTourage Pocket eDGe Dualbook off Woot recently, and while I'm waiting for it to show up in the mail (shipping to APO takes forever sometimes) I've been downloading updates and reading about all the tinkering you've done.
Now for the hook: I ran some virus scans this morning, and when McAfee Stinger (version 10.1.0.1629, 27 May 2011 virus definitions) reached the folder I've downloaded my Edge updates into it came up with warnings. The problem appears to be a TrueType font (rursuscompactmono_2.ttf) which is in multiple updates and is susceptible to exploits. Stinger claims it's infected with a virus called Exploit-CVE-2010-2738. Frankly I don't know what to make of this, since I doubt Android has the same vulnerabilities, but this seems like something which the good people of Mobilereads should be aware of.
The file in question appears in these archives & paths:

ermine-1.01.002.zip\system2.zip\EsiDictionary.apk\rursusc ompactmono_2.ttf

p-update.zip.ermine-0.9.zip\system2.zip\EsiDictionary.apk\rursuscompac tmono_2.ttf

PocketEdge_updates_by_Mark_Rehorst.zip\update.zip. ermine-0.9.PE\system2.zip\EsiDictionary.apk\rursuscompact mono_2.ttf

update.zip\system2.zip\EsiDictionary.apk\rursuscom pactmono_2.ttf
DoghouseReilley is offline   Reply With Quote
Old 07-24-2011, 07:11 PM   #2
emusan
lol
emusan can extract oil from cheeseemusan can extract oil from cheeseemusan can extract oil from cheeseemusan can extract oil from cheeseemusan can extract oil from cheeseemusan can extract oil from cheeseemusan can extract oil from cheeseemusan can extract oil from cheese
 
emusan's Avatar
 
Posts: 472
Karma: 1031
Join Date: May 2011
Device: eDGe
Quote:
Originally Posted by DoghouseReilley View Post
McAfee Stinger
There's your problem, McAfee gives more false positives than pretty much any other antivirus out there.
emusan is offline   Reply With Quote
Advert
Old 07-24-2011, 07:49 PM   #3
ivanjt
Guru
ivanjt ought to be getting tired of karma fortunes by now.ivanjt ought to be getting tired of karma fortunes by now.ivanjt ought to be getting tired of karma fortunes by now.ivanjt ought to be getting tired of karma fortunes by now.ivanjt ought to be getting tired of karma fortunes by now.ivanjt ought to be getting tired of karma fortunes by now.ivanjt ought to be getting tired of karma fortunes by now.ivanjt ought to be getting tired of karma fortunes by now.ivanjt ought to be getting tired of karma fortunes by now.ivanjt ought to be getting tired of karma fortunes by now.ivanjt ought to be getting tired of karma fortunes by now.
 
Posts: 858
Karma: 1027478
Join Date: Aug 2010
Location: South of France
Device: kindle dx; eDGe
Quote:
Originally Posted by emusan View Post
There's your problem, McAfee gives more false positives than pretty much any other antivirus out there.
How true. At one stage we were thinking of charging extra every time someone brought in a notebook complaining the McAfee AV said they hab a virus and could we clean it up. The other thing is that it also seems to miss several as well.
ivanjt is offline   Reply With Quote
Old 07-24-2011, 08:21 PM   #4
Filark
Armed with a smile :)
Filark ought to be getting tired of karma fortunes by now.Filark ought to be getting tired of karma fortunes by now.Filark ought to be getting tired of karma fortunes by now.Filark ought to be getting tired of karma fortunes by now.Filark ought to be getting tired of karma fortunes by now.Filark ought to be getting tired of karma fortunes by now.Filark ought to be getting tired of karma fortunes by now.Filark ought to be getting tired of karma fortunes by now.Filark ought to be getting tired of karma fortunes by now.Filark ought to be getting tired of karma fortunes by now.Filark ought to be getting tired of karma fortunes by now.
 
Filark's Avatar
 
Posts: 1,421
Karma: 2463560
Join Date: Sep 2009
Location: California, USA
Device: enTourage eDGe & Pocket eDGe, Samsung Galaxy Note II
Darn! I get McAfee free and thought it was working well for me. Guess I'll have to rethink.

Welcome to MobileRead, Doghouse!
Filark is offline   Reply With Quote
Old 07-24-2011, 10:06 PM   #5
emusan
lol
emusan can extract oil from cheeseemusan can extract oil from cheeseemusan can extract oil from cheeseemusan can extract oil from cheeseemusan can extract oil from cheeseemusan can extract oil from cheeseemusan can extract oil from cheeseemusan can extract oil from cheese
 
emusan's Avatar
 
Posts: 472
Karma: 1031
Join Date: May 2011
Device: eDGe
I have never once paid for computer security, there are many free options out there for both the incredibly geeky and non-geeky alike, if you would like some recommendations I can give you some...
emusan is offline   Reply With Quote
Advert
Old 07-25-2011, 03:35 PM   #6
DoghouseReilley
Junior Member
DoghouseReilley began at the beginning.
 
DoghouseReilley's Avatar
 
Posts: 7
Karma: 10
Join Date: Jul 2011
Location: KMC, De
Device: Entourage PocketEdge; Motorola Droid2
Thanks for the welcome. Re: AV solutions, I switched over to MS Security Essentials for my main desktop a few months ago, but I run portable and online virus scans from various providers now and again since every program seems to have slightly different blind spots and this was such an occasion.
Back to OP topic, I shall proceed on the assumption that it's nothing to worry about, and my conscience is salved by knowing I at least pointed it out to the community.
In the meantime, still waiting for the Edge to show up in the mail. (Probably another two weeks, given previous experience with Woot shipping.)
DoghouseReilley is offline   Reply With Quote
Old 07-25-2011, 04:21 PM   #7
muranternet
Connoisseur
muranternet began at the beginning.
 
Posts: 75
Karma: 10
Join Date: May 2011
Device: Kindle 3/Sony PRS-300/Nook Color running CM7/P eDGe
FYI I haven't seen any alerts from Kapersky, Malwarebytes or Avast. I can't speak to AVG since I stopped using it a year ago. McAfee does throw a lot of false positives. IMHO it's second only to Trend Micro in false positives/missed actual malware.
muranternet is offline   Reply With Quote
Old 07-25-2011, 04:25 PM   #8
ivanjt
Guru
ivanjt ought to be getting tired of karma fortunes by now.ivanjt ought to be getting tired of karma fortunes by now.ivanjt ought to be getting tired of karma fortunes by now.ivanjt ought to be getting tired of karma fortunes by now.ivanjt ought to be getting tired of karma fortunes by now.ivanjt ought to be getting tired of karma fortunes by now.ivanjt ought to be getting tired of karma fortunes by now.ivanjt ought to be getting tired of karma fortunes by now.ivanjt ought to be getting tired of karma fortunes by now.ivanjt ought to be getting tired of karma fortunes by now.ivanjt ought to be getting tired of karma fortunes by now.
 
Posts: 858
Karma: 1027478
Join Date: Aug 2010
Location: South of France
Device: kindle dx; eDGe
Another thing you have to consider, it is being flagged as a windows virus - it runs on windows. The PE uses Android - based on linux - therefore, even if there is a virus, not very likely, it won't work anyway.

I#ve had a look at those files and there appears to nothing untoward in them - at least on the download I have.
ivanjt is offline   Reply With Quote
Old 07-25-2011, 08:56 PM   #9
obsessed2
Wizard
obsessed2 ought to be getting tired of karma fortunes by now.obsessed2 ought to be getting tired of karma fortunes by now.obsessed2 ought to be getting tired of karma fortunes by now.obsessed2 ought to be getting tired of karma fortunes by now.obsessed2 ought to be getting tired of karma fortunes by now.obsessed2 ought to be getting tired of karma fortunes by now.obsessed2 ought to be getting tired of karma fortunes by now.obsessed2 ought to be getting tired of karma fortunes by now.obsessed2 ought to be getting tired of karma fortunes by now.obsessed2 ought to be getting tired of karma fortunes by now.obsessed2 ought to be getting tired of karma fortunes by now.
 
obsessed2's Avatar
 
Posts: 1,041
Karma: 4694121
Join Date: Apr 2011
Location: Virginia
Device: Pocket Edge X 2 , Edge, gTab, Kindle Fire, Nextbook 7S
I downloaded both the EE and PE Ermine updates which got a clean bill of health from Norton.
obsessed2 is offline   Reply With Quote
Old 07-26-2011, 10:14 AM   #10
kennyminot
Groupie
kennyminot composes epic poetry in binary.kennyminot composes epic poetry in binary.kennyminot composes epic poetry in binary.kennyminot composes epic poetry in binary.kennyminot composes epic poetry in binary.kennyminot composes epic poetry in binary.kennyminot composes epic poetry in binary.kennyminot composes epic poetry in binary.kennyminot composes epic poetry in binary.kennyminot composes epic poetry in binary.kennyminot composes epic poetry in binary.
 
kennyminot's Avatar
 
Posts: 183
Karma: 90022
Join Date: May 2011
Location: Louisville, KY
Device: HTC EVO View 4G, HTC Wildfire S, Asus T91MT
I've been using AVAST now seemingly since the beginning of time. I like that a sultry woman's voice tells me when my virus files have been updated. Makes me feel like a stud.
kennyminot is offline   Reply With Quote
Old 07-26-2011, 11:39 AM   #11
emusan
lol
emusan can extract oil from cheeseemusan can extract oil from cheeseemusan can extract oil from cheeseemusan can extract oil from cheeseemusan can extract oil from cheeseemusan can extract oil from cheeseemusan can extract oil from cheeseemusan can extract oil from cheese
 
emusan's Avatar
 
Posts: 472
Karma: 1031
Join Date: May 2011
Device: eDGe
Quote:
Originally Posted by kennyminot View Post
I've been using AVAST now seemingly since the beginning of time. I like that a sultry woman's voice tells me when my virus files have been updated. Makes me feel like a stud.
I used to use avast a lot, but around two years ago I stopped as it seemed to become more and more bloated without really finding a lot of stuff(I do some testing of viruses and antiviruses in VM's for fun). I've since moved to MSE with Comodo Defense+(for heuristics) and firewall, and sandboxie(best protection ever if you know how to use it imho).
emusan is offline   Reply With Quote
Old 07-26-2011, 04:09 PM   #12
DoghouseReilley
Junior Member
DoghouseReilley began at the beginning.
 
DoghouseReilley's Avatar
 
Posts: 7
Karma: 10
Join Date: Jul 2011
Location: KMC, De
Device: Entourage PocketEdge; Motorola Droid2
Quote:
Originally Posted by ivanjt View Post
Another thing you have to consider, it is being flagged as a windows virus - it runs on windows. The PE uses Android - based on linux - therefore, even if there is a virus, not very likely, it won't work anyway.
That is my default assumption as well. As I mentioned, I didn't think this was an issue that would actually affect Android devices, but wanted to see what the forum thought about it.
A Woot shirt for my wife which I ordered on the 11th of June arrived yesterday... so the wait will probably be another two weeks minimum. In the meantime I amuse myself by designing cases for it on Gelaskins.
DoghouseReilley is offline   Reply With Quote
Reply


Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
The Ermine "Tweaks" Thread (Gapps, Ermine Bugs, and More) kennyminot enTourage eDGe 136 09-09-2012 02:53 PM
Adobe Reader 9 new exploit in the wild doctorow News 2 02-20-2009 03:38 PM
iLiad Huge exploit found in 2.7 arivero iRex Developer's Corner 86 11-26-2006 04:49 PM
Adobe Acrobat subject to remote exploit Alexander Turcic News 3 09-16-2006 05:29 AM
Serious exploit in Greasemonkey 0.4 Alexander Turcic Lounge 2 07-19-2005 04:59 AM


All times are GMT -4. The time now is 06:57 AM.


MobileRead.com is a privately owned, operated and funded community.