CERT-In Advisory
CIAD-2018-0023
Multiple Vulnerabilities in Google Android
Original Issue Date: September 18, 2018
Severity Rating: High
Software Affected
- Google Android versions 7.0, 7.1.1, 7.1.2, 8.0, 8.1, 9.0
Overview
Multiple vulnerabilities have been reported in Google Android that could allow a remote attacker to cause Denial of service condition, disclosure of system and user information, obtain potentially sensitive information, and execution of arbitrary code on the targeted system.
Description
These vulnerabilities exist in Android runtime, Library, framework, Media framework, System, Kernel and Qualcomm components of Google Android. A remote attacker could exploit these vulnerabilities by hosting a specially crafted file designed to exploit the vulnerabilities.
Successful exploitation of these vulnerabilities could allow remote attacker to execute arbitrary code, Denial of service condition, disclosure of system and user information, obtain potentially sensitive information on the targeted system.
Solution
Apply appropriate over-the-air updates as mentioned by various device manufacturers.
Vendor Information
Android
https://source.android.com/security/bulletin/2018-09-01
References
Android
https://source.android.com/security/bulletin/2018-09-01
CVE Name
CVE-2018-9466
CVE-2018-9467
CVE-2018-9469
CVE-2018-9470
CVE-2018-9471
CVE-2018-9472
CVE-2018-9474
CVE-2018-9440
CVE-2018-9475
CVE-2018-9478
CVE-2018-9479
CVE-2018-9456
CVE-2018-9477
CVE-2018-9480
CVE-2018-9481
CVE-2018-9482
CVE-2018-9483
CVE-2018-9484
CVE-2018-9485
CVE-2018-9486
CVE-2018-9487
CVE-2018-9488
CVE-2018-9411
CVE-2018-9427
CVE-2018-9468
CVE-2018-11816
CVE-2018-11261
CVE-2018-11836
CVE-2018-11842
CVE-2018-11898
CVE-2018-11270
CVE-2018-11950
CVE-2018-5866
CVE-2018-11824
CVE-2018-3588
CVE-2018-11951
CVE-2018-11952
CVE-2018-5871
CVE-2018-5914
CVE-2018-11288
CVE-2018-11285
CVE-2018-11290
CVE-2018-11292
CVE-2018-11287
CVE-2018-11846
CVE-2018-11855
CVE-2018-11857
CVE-2018-11858
CVE-2018-11866
CVE-2018-11865
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|