Canadian Centre for Cyber Security · English · AV17-018Android security bulletin – February 2017hrough remote code execution on affected devices using multiple methods such as email, web browsing, and MMS when processing media files.
CVE References: CVE-2016-5552, CVE-2016-8414, CVE-2016-8418, CVE-2016-8480, CVE-2016-8481, CVE-2014-9914, CVE-2016-10044, CVE-2017-0405, CVE-2017-0406, CVE-2017-0407, CVE-2017-0408, CVE-2017-0409, CVE-2017-0410, CVE-2017-0411, CVE-2017-0412, CVE-2017-0413, CVE-2017-0414, CVE-2017-0415, CVE-2017-0416, CVE-2017-0417, CVE-2017-0418, CVE-2017-0419, CVE-2017-0420, CVE-2017-0421, CVE-2017-0422, CVE-2017-0423, CVE-2017-0424, CVE-2017-0425, CVE-2017-0426, CVE-2017-0427, CVE-2017-0428, CVE-2017-0429, CVE-2017-0430, CVE-2017-0431, CVE-2017-0432, CVE-2017-0433, CVE-2017-0434, CVE-2017-0435, CVE-2017-0436, CVE-2017-0437, CVE-2017-0438, CVE-2017-0439CVE-2017-0440, CVE-2017-0441, CVE-2017-0442, CVE-2017-0443, CVE-2017-0444, CVE-2017-0445, CVE-2017-0446, CVE-2017-0447, CVE-2017-0448, CVE-2017-0449, CVE-2017-0450, CVE-2017-0451.
Suggested Action
CCIRC recommends that system administrators look with their respected Android phone vendor and carrier when the update will be available and test and deploy the vendor-released updates to affected applications accordingly.
References
Android Security Bulletin:
https://source.android.com/security/bulletin/2017-02-01.html
Official advisory ↗