SB2017041317 - Improper Neutralization of Special Elements in Output Used by a Downstream Component in Google, Google Android 



SB2017041317 - Improper Neutralization of Special Elements in Output Used by a Downstream Component in Google, Google Android

Published: April 13, 2017 Updated: August 8, 2020

Security Bulletin ID SB2017041317
Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Improper Neutralization of Special Elements in Output Used by a Downstream Component (CVE-ID: CVE-2016-1155)

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

HTTP header injection vulnerability in the URLConnection class in Android OS 2.2 through 6.0 allows remote attackers to execute arbitrary scripts or set arbitrary values in cookies.


Remediation

Install update from vendor's website.