![]() |
#1 |
Junior Member
![]() Posts: 7
Karma: 10
Join Date: Jul 2011
Location: KMC, De
Device: Entourage PocketEdge; Motorola Droid2
|
Exploit-CVE-2010-2738 in Ermine updates?
TL,DR: Multiple versions of the update.zip for the Pocket Edge are being flagged by McAfee Stinger as having a virus.
Well met, strangers. I bought an enTourage Pocket eDGe Dualbook off Woot recently, and while I'm waiting for it to show up in the mail (shipping to APO takes forever sometimes) I've been downloading updates and reading about all the tinkering you've done. Now for the hook: I ran some virus scans this morning, and when McAfee Stinger (version 10.1.0.1629, 27 May 2011 virus definitions) reached the folder I've downloaded my Edge updates into it came up with warnings. The problem appears to be a TrueType font (rursuscompactmono_2.ttf) which is in multiple updates and is susceptible to exploits. Stinger claims it's infected with a virus called Exploit-CVE-2010-2738. Frankly I don't know what to make of this, since I doubt Android has the same vulnerabilities, but this seems like something which the good people of Mobilereads should be aware of. The file in question appears in these archives & paths: ermine-1.01.002.zip\system2.zip\EsiDictionary.apk\rursusc ompactmono_2.ttf p-update.zip.ermine-0.9.zip\system2.zip\EsiDictionary.apk\rursuscompac tmono_2.ttf PocketEdge_updates_by_Mark_Rehorst.zip\update.zip. ermine-0.9.PE\system2.zip\EsiDictionary.apk\rursuscompact mono_2.ttf update.zip\system2.zip\EsiDictionary.apk\rursuscom pactmono_2.ttf |
![]() |
![]() |
![]() |
#2 |
lol
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 472
Karma: 1031
Join Date: May 2011
Device: eDGe
|
|
![]() |
![]() |
Advert | |
|
![]() |
#3 |
Guru
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 858
Karma: 1027478
Join Date: Aug 2010
Location: South of France
Device: kindle dx; eDGe
|
How true. At one stage we were thinking of charging extra every time someone brought in a notebook complaining the McAfee AV said they hab a virus and could we clean it up. The other thing is that it also seems to miss several as well.
|
![]() |
![]() |
![]() |
#4 |
Armed with a smile :)
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 1,421
Karma: 2463560
Join Date: Sep 2009
Location: California, USA
Device: enTourage eDGe & Pocket eDGe, Samsung Galaxy Note II
|
Darn!
![]() Welcome to MobileRead, Doghouse! ![]() |
![]() |
![]() |
![]() |
#5 |
lol
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 472
Karma: 1031
Join Date: May 2011
Device: eDGe
|
I have never once paid for computer security, there are many free options out there for both the incredibly geeky and non-geeky alike, if you would like some recommendations I can give you some...
|
![]() |
![]() |
Advert | |
|
![]() |
#6 |
Junior Member
![]() Posts: 7
Karma: 10
Join Date: Jul 2011
Location: KMC, De
Device: Entourage PocketEdge; Motorola Droid2
|
Thanks for the welcome. Re: AV solutions, I switched over to MS Security Essentials for my main desktop a few months ago, but I run portable and online virus scans from various providers now and again since every program seems to have slightly different blind spots and this was such an occasion.
Back to OP topic, I shall proceed on the assumption that it's nothing to worry about, and my conscience is salved by knowing I at least pointed it out to the community. In the meantime, still waiting for the Edge to show up in the mail. (Probably another two weeks, given previous experience with Woot shipping.) |
![]() |
![]() |
![]() |
#7 |
Connoisseur
![]() Posts: 75
Karma: 10
Join Date: May 2011
Device: Kindle 3/Sony PRS-300/Nook Color running CM7/P eDGe
|
FYI I haven't seen any alerts from Kapersky, Malwarebytes or Avast. I can't speak to AVG since I stopped using it a year ago. McAfee does throw a lot of false positives. IMHO it's second only to Trend Micro in false positives/missed actual malware.
|
![]() |
![]() |
![]() |
#8 |
Guru
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 858
Karma: 1027478
Join Date: Aug 2010
Location: South of France
Device: kindle dx; eDGe
|
Another thing you have to consider, it is being flagged as a windows virus - it runs on windows. The PE uses Android - based on linux - therefore, even if there is a virus, not very likely, it won't work anyway.
I#ve had a look at those files and there appears to nothing untoward in them - at least on the download I have. |
![]() |
![]() |
![]() |
#9 |
Wizard
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 1,041
Karma: 4694121
Join Date: Apr 2011
Location: Virginia
Device: Pocket Edge X 2 , Edge, gTab, Kindle Fire, Nextbook 7S
|
I downloaded both the EE and PE Ermine updates which got a clean bill of health from Norton.
|
![]() |
![]() |
![]() |
#10 |
Groupie
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 183
Karma: 90022
Join Date: May 2011
Location: Louisville, KY
Device: HTC EVO View 4G, HTC Wildfire S, Asus T91MT
|
I've been using AVAST now seemingly since the beginning of time. I like that a sultry woman's voice tells me when my virus files have been updated. Makes me feel like a stud.
|
![]() |
![]() |
![]() |
#11 |
lol
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 472
Karma: 1031
Join Date: May 2011
Device: eDGe
|
I used to use avast a lot, but around two years ago I stopped as it seemed to become more and more bloated without really finding a lot of stuff(I do some testing of viruses and antiviruses in VM's for fun). I've since moved to MSE with Comodo Defense+(for heuristics) and firewall, and sandboxie(best protection ever if you know how to use it imho).
|
![]() |
![]() |
![]() |
#12 | |
Junior Member
![]() Posts: 7
Karma: 10
Join Date: Jul 2011
Location: KMC, De
Device: Entourage PocketEdge; Motorola Droid2
|
Quote:
A Woot shirt for my wife which I ordered on the 11th of June arrived yesterday... so the wait will probably be another two weeks minimum. In the meantime I amuse myself by designing cases for it on Gelaskins. |
|
![]() |
![]() |
![]() |
|
![]() |
||||
Thread | Thread Starter | Forum | Replies | Last Post |
The Ermine "Tweaks" Thread (Gapps, Ermine Bugs, and More) | kennyminot | enTourage eDGe | 136 | 09-09-2012 02:53 PM |
Adobe Reader 9 new exploit in the wild | doctorow | News | 2 | 02-20-2009 03:38 PM |
iLiad Huge exploit found in 2.7 | arivero | iRex Developer's Corner | 86 | 11-26-2006 04:49 PM |
Adobe Acrobat subject to remote exploit | Alexander Turcic | News | 3 | 09-16-2006 05:29 AM |
Serious exploit in Greasemonkey 0.4 | Alexander Turcic | Lounge | 2 | 07-19-2005 04:59 AM |