Google patched 17 security holes in May's Android update
Google is preparing to release its May Android update this week, focusing heavily on critical vulnerabilities on media servers.
There will be 17 critical vulnerabilities patched in the May update, including six vulnerabilities in the media server (Media Server) of the Android library. The media server library is the subject of interest since July 2015 when the first Stagefirst bug was announced. Android's media server has been patched every time Google updates since August 2015.
All 6 errors on the media server were patched in May (CVE-2017-0587, CVE-2017-0588, CVE-2017-0589, CVE-2017-0590, CVE-2017-0591 and CVE-2017-0592) are related to remote code execution vulnerabilities.
Google warns that " remote code execution vulnerabilities in media servers allow hackers to use a file that corrupts memory during transmission and processing of media data ". This problem is rated as important (Critical) because of the ability to execute remote code right in the process of media server.
This month, Google also patched 7 other bugs on the media server, including three privilege escalation vulnerabilities that are highly influential (CVE-2017-0592, CVE-2017-0595 and CVE-2017- 0596).
Google advises that " privileged escalation vulnerabilities on media servers allow standalone applications on the device to execute random code during the privilege process ". " This problem is rated high because it can be used to access tasks that normally third-party applications cannot access ."
- How to check and update the version of Android operating system in use
- Microsoft silently updated Windows 10 to patch 2 serious security holes
- Google Chrome again urgently updates to patch serious security holes
- New version of Firefox patched some additional security flaws
- Detects 146 security holes in pre-installed Android applications
- Google releases an urgent security patch for Chrome, users take note!
- Google warns of 5 serious security holes in Chrome, recommends users to update the patch immediately
- Android 10 has 193 security errors that need to be processed before it launches on September 1
- Chrome and Firefox have a serious security flaw, there is no way to fix it
- McAfee software has a vulnerability that allows hackers to run code with system privileges on Windows
- The security flaw threatens more than 2 billion Google Chrome users
- Fortnite for Android has a security vulnerability
- Detect 2 serious security holes in the Zoom application
- Samba updated the patch and patched the DoS vulnerability
- Google's new Jarlsberg server system: full of holes like 'cheese'