Number: AV16-070
Date: 3 May 2016
Purpose
The purpose of this advisory is to bring attention to the Android Security Bulletin for May.
Assessment
The Android Security Bulleting addresses a security update for 40 vulnerabilities (12 Critical, 19 High, 8 Moderate and 1 Low) that could potentially enable remote code execution on affected devices. This update is also distributed to the Android Open Source Project (AOSP) repository.
CVE References: CVE-2015-0569, CVE-2015-0570, CVE-2015-0571, CVE-2015-1805, CVE-2016-0705, CVE-2016-0774, CVE-2016-2060, CVE-2016-2428, CVE-2016-2429, CVE-2016-2430, CVE-2016-2431, CVE-2016-2432, CVE-2016-2434, CVE-2016-2435, CVE-2016-2436, CVE-2016-2437, CVE-2016-2438, CVE-2016-2439, CVE-2016-2440, CVE-2016-2441, CVE-2016-2442, CVE-2016-2443, CVE-2016-2444, CVE-2016-2445, CVE-2016-2446, CVE-2016-2447, CVE-2016-2448, CVE-2016-2449, CVE-2016-2450, CVE-2016-2451, CVE-2016-2452, CVE-2016-2453, CVE-2016-2454, CVE-2016-2456, CVE-2016-2457, CVE-2016-2458, CVE-2016-2459, CVE-2016-2460,CVE-2016-2461, CVE-2016-2462
Suggested action
CCIRC recommends that system administrators look with their respected Android phone vendor and carrier when the update will be available and test and deploy the vendor-released updates to affected applications accordingly.
References
Android web site: https://source.android.com/security/bulletin/2016-05-01.html