:bien:Today I found some of the patches in the CM12.1 tree and added them locally to a fresh synced CM11 tree.
Fixes for Sonivox, Skia and libstagefright are included. I'm currently trying to build the modified version and test it.
Overview of all updates (not all concerns CM11/Android 4.4)
https://groups.google.com/forum/#!topic/android-security-updates/_Rm-lKnS2M8
Edit: The build process finished without errors, not tested on device yet. But also no PoC atm to test the build against.
If anyone is interested I can provide the build file. But be warned, without any any warranty, absolutely and totally untested!
greetings
=>Proof of Concept. A piece of software which is able to exploit the bug and which could be used to test the new compiled CM against.
I'm currently building from the same source tree for the serrano3gxx, build is in process.:bien:
friend please do not forget 3g model. Thanks for your time.
The latest build finished without errors this night. Installed it to my device, boots up ok and the Stagefright Detector does not complain anything.
In addition to the CVE's tested by the Detector App, the following bugs should be resolved:
- Remote Code Execution Vulnerability in libFLAC CVE-2014-9082
- Remote Code Execution Vulnerability in Skia CVE-2015-3877
- Remote Code Execution Vulnerabilities in Sonivox CVE-2015-3874
- Elevation of Privilege Vulnerability in KeyStore CVE-2015-3863
- Patches for reading ID3 Tags CVE-2015-6603
- Various other fixes, dont know the corresponding CVEs
Download 1: https://mega.nz/#!6t0w3CKY
Download 2 (mirror): http://www.imagenetz.de/faf551523/cm-11-20151011-UNOFFICIAL-serranoltexx.zip.html
md5sum: 101113572bb9ab557d7a38267a1bd487
sha1sum: 8a5c1b2a976c4bcd6b6fdcfb1010517eb8b8977d
I'm currently building from the same source tree for the serrano3gxx, build is in process.
I'll add d/l links here as soon as its finished.
Edit: The build for serrano3gxx has finished!
Download 1: https://mega.nz/#!qpF3RZzZ
Download 2 (mirror): todo
md5sum: da68022667cf6ec9355566fb1d39fc77
sha1sum: a8bd7961fe61f124f9a904e2785eb8c362f4a7f7
Note: Even if the name is different (cm-11-20151011-UNOFFICIAL vs. cm-11-20151012-UNOFFICIAL), the sources are the same.
The 3g build is absolutely untested, but should work. Please give me some feedback if everything is fine, I would add it here as an information for others.
greetings
Didier
Moved the files to androidfilehost and updated the links, sorry. It seems that the mega d/l was broken.
samsung released a new update http://live.samsung-updates.com/index.php?device=GT-I9195
hopefully both the release is only 4 days old so should be for both.
/*
* Your warranty is now void.
*
* We are not responsible for bricked devices, dead SD cards,
* thermonuclear war, or you getting fired because the alarm app failed. Please
* do some research if you have any concerns about features included in this ROM
* before flashing it! YOU are choosing to make these modifications, and if
* you point the finger at us for messing up your device, we will laugh at you.
*
*/
I'm currently building from the same source tree for the serrano3gxx, build is in process.:bien:
friend please do not forget 3g model. Thanks for your time.
But someone can share a "rescue" link for to download ,please ? i want to instal this last CM11 too ......and CMdownload is down since some days ... :crying: