Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Editor Blogs > Security

July 17th, 2012, 14:52 GMT · By

BLOG

Flaw in Kindle Touch Browser Allows Attacker to Steal Root Credentials

SHARE:

Adjust text size:


Researchers find vulnerability in Kindle Touch's web browser Enlarge picture - Researchers find vulnerability in Kindle Touch's web browser
A security hole that affects the web browser in Amazon’s Kindle Touch allows an attacker to execute arbitrary shell commands with root privileges if he can convince a user to navigate to a specially crafted webpage.

Furthermore, the vulnerability could be leveraged to gain access to the device’s operating system and steal the user’s Amazon account credentials, The H informs. A cybercriminal can use these credentials to make purchases on the victim’s behalf.

Researchers from heise Security have published a video to demonstrate the existence of the flaw in eBook readers that with the 5.1.0 firmware variant. They’ve managed to get the Kindle to send the /etc/shadow file – which contains the root password hash – to an arbitrary server.

Fortunately, Amazon is already working on a patch and some users are reporting that the newly shipped devices, which come with a 5.1.1 version of the firmware, are not susceptible to the attack.
FILED UNDER:
vulnerability
Kindle
Amazon

TELL US WHAT YOU THINK:

864 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Flaw in Artema Hybrid Terminals Allows Hackers to Collect Payment Card Details

Trend Micro Confirms Yahoo! Mail Flaw Possible Cause of “Android Botnet”

Experts Find Filter Bypass Vulnerabilities in Barracuda Appliances (Video, Updated)

Minecraft Flaw Exposes Gamer Accounts, Researchers Find

Security Brief: Yahoo!, NVIDIA, AndroidForums, Formspring, Nexus Q Hacked

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM