Number: AV16-002
Date: 8 January 2016
Purpose
The purpose of this advisory is to bring attention to the Android Security Bulletin for January.
Assessment
The Android Security Bulletin addresses a security update for 12 vulnerabilities (5 Critical, 2 High, and 6 Moderate) that could potentially enable remote code execution on affected devices. This update is also distributed to the Android Open Source Project (AOSP) repository.
CVE References: CVE-2015-6636, CVE-2015-6637, CVE-2015-6638, CVE-2015-6639, CVE-2015-6640, CVE-2015-6641, CVE-2015-6642, CVE-2015-6643, CVE-2015-5310, CVE-2015-6644, CVE-2015-6645, CVE-2015-6646
Suggested Action
CCIRC recommends that system administrators look with their respected Android phone vendor and carrier when the update will be available and test and deploy the vendor-released updates to affected applications accordingly.
References:
- Android web site: http://source.android.com/security/bulletin/2016-01-01.html
- CVE web site: https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-6647