SB2017041317 - Improper Neutralization of Special Elements in Output Used by a Downstream Component in Google, Google Android
Published: April 13, 2017 Updated: August 8, 2020
Security Bulletin ID
SB2017041317
Severity
High
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Code execution
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper Neutralization of Special Elements in Output Used by a Downstream Component (CVE-ID: CVE-2016-1155)
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
HTTP header injection vulnerability in the URLConnection class in Android OS 2.2 through 6.0 allows remote attackers to execute arbitrary scripts or set arbitrary values in cookies.
Remediation
Install update from vendor's website.