Google patched 17 security holes in May's Android update
There will be 17 critical vulnerabilities patched in the May update, including six vulnerabilities in the media server (Media Server) of the Android library. The media server library is the subject of interest since July 2015 when the first Stagefirst bug was announced. Android's media server has been patched every time Google updates since August 2015.
All 6 errors on the media server were patched in May (CVE-2017-0587, CVE-2017-0588, CVE-2017-0589, CVE-2017-0590, CVE-2017-0591 and CVE-2017-0592) are related to remote code execution vulnerabilities.
Google warns that " remote code execution vulnerabilities in media servers allow hackers to use a file that corrupts memory during transmission and processing of media data ". This problem is rated as important (Critical) because of the ability to execute remote code right in the process of media server.
This month, Google also patched 7 other bugs on the media server, including three privilege escalation vulnerabilities that are highly influential (CVE-2017-0592, CVE-2017-0595 and CVE-2017- 0596).
Google advises that " privileged escalation vulnerabilities on media servers allow standalone applications on the device to execute random code during the privilege process ". " This problem is rated high because it can be used to access tasks that normally third-party applications cannot access ."
- How to check and update the version of Android operating system in use
You should read it
- How to check and update the version of Android operating system in use
- List of phones eligible for Android 12 Beta upgrade from today
- Instructions for updating Android apps
- How is Android One and Android Go different?
- Millions of devices running Android 4.1.1 may have the bug 'Heart bleeding'
- All you need to know about Android Pie
- Leaked Android update 5.1
- What is Android TV Box?
May be interested
- McAfee software has a vulnerability that allows hackers to run code with system privileges on Windowsthis vulnerability was patched shortly after mcafee enterprise received a report from security researchers.
- The security flaw threatens more than 2 billion Google Chrome usersjust released three weeks ago, chrome 81 version contained two dangerous security holes that allowed hackers to attack and control the entire computer system of the victim.
- Fortnite for Android has a security vulnerabilitysecurity experts at google have discovered a security hole in epic games' fortnite game installer. by taking advantage of an application using an external memory system to store data, hackers can invade the device to download and install malware.
- Detect 2 serious security holes in the Zoom applicationrecently, cisco talos security researchers have discovered two serious security holes in the zoom application. these vulnerabilities allow hackers to attack and infiltrate the computers of people in the group chat.
- Samba updated the patch and patched the DoS vulnerabilitysamba has fixed security holes including two denial of service errors - dos, so that hackers can easily attack directly on smbd service.
- Google's new Jarlsberg server system: full of holes like 'cheese'a new online solution from google for web developers, including server systems with a lot of current security security holes ...
- New security vulnerabilities on iOS 12.1 allow access to contacts and phone callsa youtuber named jose rodrigue discovered a serious security flaw of ios 12.1 update, allowing to bypass the lock screen of all iphones without the need for a password, face id or fingerprint.
- Google: Play Protect helped cut 20% of malicious Android application installations by 2018to reschedule, google recently officially announced the security & privacy year in review report periodically. basically, this is an overall report that details how mountain view giants have made it more secure for more than 2 billion android devices worldwide.
- Instructions for updating Android appsyou can choose one or more of the applications on the list to have on your phone to update android apps.
- Warning of dangerous vulnerabilities on WinRAR, users should uninstall or upgrade to a new versionrarlab, the developer of winrar, has just released an urgent update to patch a dangerous vulnerability in their software.