谷歌将一些弱小的库从安卓代码移除Google Removes Vulnerable Library from Android

Posted cannovo

tags:

篇首语:本文由小常识网(cha138.com)小编为大家整理,主要介绍了谷歌将一些弱小的库从安卓代码移除Google Removes Vulnerable Library from Android相关的知识,希望对你有一定的参考价值。

Google this week released the November 2018 set of security patches for its android platform, which address tens of Critical and High severity vulnerabilities in the operating system.

The addressed issues include remote code execution bugs, elevation of privilege flaws, and information disclosure vulnerabilities, along with a denial of service. Impacted components include Framework, Media framework, System, and Qualcomm components.

“The most severe vulnerability in this section could enable a proximate attacker using a specially crafted file to execute arbitrary code within the context of a privileged process,” Google explains.

The Internet giant also announced that the Libxaac library has been marked as experimental and is no longer used in production of Android builds. The reason for this is the discovery of multiple vulnerabilities in the library, and Google lists 18 CVEs impacting it.

As usual, the search company split the fixes into two parts, with the 2018-11-01 security patch level, addressing 17 flaws, including four rated Critical severity (all of which impact Media framework).

This security patch level fixes 7 elevation of privilege bugs (two rated Critical, four High severity, and one Medium), three remote code execution bugs (two Critical and one High severity), six information disclosure issues (all rated High severity) and one denial of service (Medium).

The 2018-11-05 security patch level, on the other hand, patches 19 issues, three of which were rated Critical.

Two of the bugs impact the Framework component, while the remaining 17 were addressed in Qualcomm components, including 14 issues in Qualcomm closed-source components (3 Critical and 11 High risk).

Vag COM , TCS CDP , VAS5054A , GM Tech2 , Iprog+ Programmer , Orange 5 programmer , SBB3 PRO3 Key Programmer , wiTech MicroPod II , T300+ Key Programmer, Iprog, Scania VCI3, mercedes star diagnostic, Porsche Piwis, vocom 88890300, Renault CAN Clip, SBB Key Programmer, NEXIQ USB Link

According to Google, it has no reports of active customer exploitation or abuse of these issues. The company also notes that exploitation of vulnerabilities is more difficult on newer versions of Android and encourages users to update as soon as possible.

In addition to these patches, Pixel and Nexus devices receive fixes for three additional vulnerabilities. These include an elevation of privilege in HTC components and two other bugs in Qualcomm components. All three are rated Medium severity.

“All Pixel devices running Android 9 will receive an Android 9 update as part of the November OTA. This quarterly release contains many functional updates and improvements to various parts of the Android platform and supported Pixel devices,” Google says.

A series of functional updates were also pushed to these devices, to improve performance for the use of picture-in-picture, Strongbox symmetric key generation requests, and stability for notifications.

以上是关于谷歌将一些弱小的库从安卓代码移除Google Removes Vulnerable Library from Android的主要内容,如果未能解决你的问题,请参考以下文章

谷歌将禁止所有加密货币挖矿扩展程序进入Chrome商店

孟晚舟保释后首次发声;谷歌将提前关闭Google+;phpMyAdmin发布新版本;锤子科技有限公司子公司锤子数码出现重大变更

移动端大乱战!谷歌将正式推出 Fuchsia OS,已有适配设备!

魅族联合谷歌将推出Android Go手机

打不开google play

最新:谷歌将取消I/O开发者大会,国外大公司开启在线模式