Canadian Centre for Cyber Security · English · AV17-001Android security bulletin – January 2017iven the possibility of remote code execution vulnerabilities and/or elevation of privilege vulnerabilities.
CVE References: CVE-2016-5180, CVE-2016-5345, CVE-2016-7042, CVE-2016-8412, CVE-2016-8444, CVE-2016-8415, CVE-2016-8445, CVE-2016-8446, CVE-2016-8447, CVE-2016-8448, CVE-2016-8449, CVE-2016-8450, CVE-2016-8451, CVE-2016-8452, CVE-2016-8453, CVE-2016-8454, CVE-2016-8455, CVE-2016-8456, CVE-2016-8457, CVE-2016-8458, CVE-2016-8460, CVE-2016-8461, CVE-2016-8462, CVE-2016-8463, CVE-2016-8467, CVE-2016-9754, CVE-2017-0382, CVE-2017-0383, CVE-2017-0384, CVE-2017-0385, CVE-2017-0386, CVE-2017-0387, CVE-2017-0388, CVE-2017-0389, CVE-2017-0390, CVE-2017-0391, CVE-2017-0392, CVE-2017-0393, CVE-2017-0394, CVE-2017-0403, CVE-2017-0404
Suggested action
CCIRC recommends that system administrators look with their respected Android phone vendor and carrier when the update will be available and test and deploy the vendor-released updates to affected applications accordingly.
References
Android Security Bulletin:
https://source.android.com/security/bulletin/2017-01-01.html
Official advisory ↗