CERT-In Vulnerability Note
CIVN-2020-0450
Multiple Vulnerabilities in Google Android
Original Issue Date:December 28, 2020
Severity Rating: HIGH
Software Affected
- Google Android OS builds utilizing Security Patch Levels issued prior to May 5, 2019
Overview
Multiple vulnerabilities have been reported in Google Android operating system (OS) which could enable a remote attacker to perform arbitrary code execution, gain elevated privileges, obtain sensitive information and cause denial of service condition on the targeted system.
Description
These vulnerabilities exists in Google Android due to flaws in the Media Framework, System component, Kernel component, Broadcom components, MediaTek components, Qualcomm components and Qualcomm closed-source components. A remote attacker could exploit these vulnerabilities by hosting a specially crafted file designed to exploit the vulnerabilities.
Successful exploitation of these vulnerabilities could allow remote attacker to perform arbitrary code execution within the context of a privileged process, gain elevated privileges, allow the attacker to access sensitive information from the targeted device and cause denial of service conditions on the targeted system.
Solution
Apply appropriate over-the-air updates as provided by various device manufacturers.
https://source.android.com/security/bulletin/2020-12-01
Vendor Information
Google Android
https://source.android.com/security/bulletin/2020-12-01
References
Google Android
https://source.android.com/security/bulletin/2020-12-01
Center for Internet Security
https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-google-android-os-could-allow-for-remote-code-execution_2020-162/
CVE Name
CVE-2020-0099
CVE-2020-0294
CVE-2020-0440
CVE-2020-0459
CVE-2020-0464
CVE-2020-0467
CVE-2020-0468
CVE-2020-0469
CVE-2020-0458
CVE-2020-0470
CVE-2020-0460
CVE-2020-0463
CVE-2020-15802
CVE-2020-0444
CVE-2020-0465
CVE-2020-0466
CVE-2020-0016
CVE-2020-0019
CVE-2020-0455
CVE-2020-0456
CVE-2020-0457
CVE-2020-11225
CVE-2020-11146
CVE-2020-11167
CVE-2020-11185
CVE-2020-11217
CVE-2020-3685
CVE-2020-3686
CVE-2020-3691
CVE-2020-11136
CVE-2020-11137
CVE-2020-11138
CVE-2020-11140
CVE-2020-11143
CVE-2020-11119
CVE-2020-11139
CVE-2020-11144
CVE-2020-11145
CVE-2020-11145
CVE-2020-11179
CVE-2020-11197
CVE-2020-11200
CVE-2020-11212
CVE-2020-11213
CVE-2020-11214
CVE-2020-11215
CVE-2020-11216
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|