Android Century
  • Home
  • Android Zone
    • Android Apps
    • Android Games
    • Apps APk Files
    • Games Apk Files
    • Apps Hack Tricks
  • Reviews
  • Fantasy Zone
    • Entertainment
    • Quotes and Status
    • Life Style
    • Home Made Tips
    • Hair Care
    • Skin Care
    • Fantasy Tips
  • Tricks
    • Free Recharge
    • Free Internet
    • shopping Cashback
    • Recharge Cashback
  • Tech
  • Mobiles
  • Gadgets
  • News
  • How To's
  • Software
Breaking
Loading...

Featured post

How to Take Great Photos With Apple's iPhone X

Recent Posts

Labels

  • Android Apk Files
  • Android Apps
  • Android Games
  • Apps Apk Files
  • Entertainment
  • Fantasy Tips
  • Gadgets
  • Hair Care
  • HomeMade Tips
  • How To's
  • News
  • Quotes
  • Quotes & Status
  • Recharge Cashback
  • Recharge Promo Codes
  • Shopping Cashback
  • Technology
  • skin care
Home / News / Android gets patches for critical OpenSSL, media server and kernel driver flaws

Android gets patches for critical OpenSSL, media server and kernel driver flaws

Latest Govt. Jobs 20:53:00 News Edit
p1200739

A five-month-old flaw in Android's SSL cryptographic libraries is among the 35 critical vulnerabilities Google fixed in its March security patches for the mobile OS.
The first set of patches, known as patch level 2017-03-01, is common to all patched phones and contains fixes for 36 vulnerabilities, 11 of which are rated critical and 15 high. Android vulnerabilities rated critical are those that can be exploited to execute malicious code in the context of a privileged process or the kernel, potentially leading to a full device compromise.
One of the patched vulnerabilities is located in the OpenSSL cryptographic library and also affects Google's newer BoringSSL library, which is based on OpenSSL. What's interesting is that the flaw, identified as CVE-2016-2182, was patched in OpenSSL back in September. It can be exploited by forcing the library to process an overly large certificate or certificate revocation list from an untrusted source.
It's unclear why Google has waited for almost six months to fix this vulnerability in Android. The OpenSSL developers have rated the flaw as low severity and noted in their advisory that it doesn't affect TLS connections because "record limits will reject an oversized certificate before it is parsed."
Meanwhile Google rates the flaw as critical and says that an attacker using a specially crafted file can cause memory corruption during file and data processing and execute malicious code within the context of a privileged process.
Nine critical vulnerabilities were patched in mediaserver, an Android component responsible for processing media files that has been the source of many flaws over the past two years. These vulnerabilities can potentially be exploited remotely.
Finally, one critical vulnerability was fixed in the recovery verifier component. This can be exploited locally to elevate one's privileges and execute arbitrary code inside the kernel, leading to a permanent device compromise.
As it has done since July, Google has split its monthly Android fixes into two separate batches identified by different security patch levels. These levels are expressed as a date string in Android's settings under "About phone" and indicate that the firmware contains all Android security patches up to that date.
Which fixes a phone gets within a patch level depends on the version of Android it is running. Some of the latest fixes, including that for OpenSSL, apply to phones running versions of Android as far back as 4.4.4 (KitKat); others are only for Android 7.1.1, the latest tweak of Nougat.
The reason for splitting security updates into different patch levels is to differentiate between vulnerabilities in Android software components common to all phones and those that only affect phones with certain hardware components for which chipset makers have provided custom drivers.
The second patch level for March, 2017-03-05, covers 24 critical vulnerabilities in drivers and components from MediaTek, Nvidia, Broadcom and Qualcomm, as well as in various kernel subsystems. In addition, this patch level fixes 32 high-rated vulnerabilities, 14 moderate ones and one low risk flaw.
Only the phones that contain the vulnerable drivers need to apply these patches, so not all devices will end up with the 2017-03-05 patch level.
Share on Facebook Share on Twitter Share on Google Plus

RELATED POSTS


Vodafone partners with Tecno to off...

LG G7 with iPhone X-like notch

Oppo F7 India launch confirmed
Android gets patches for critical OpenSSL, media server and kernel driver flaws Android gets patches for critical OpenSSL, media server and kernel driver flaws Reviewed by Latest Govt. Jobs on 20:53:00 Rating: 5

0 comments:

Post a Comment

Newer Post Older Post Home
Subscribe to: Post Comments ( Atom )

Search This Blog

TEST BOOK FOR GOVT ENTRANCE TEST

TEST BOOK FOR GOVT ENTRANCE TEST
Find All Latest book for preparation of SSC,RAILWAYBANK PO,RBI,BANK CLERK,GATE ME,GATE CE are available here in less prices, to check out the books click here

Translate

  • Popular Post
  • Random posts
  • Category

Popular Posts

  • Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Refer & Earn Offer:  Hey Guys! Today I make an article about Teen Patti Referral ...
  • Taotronics TT-BH22 Headphones Review
    We make it a addiction to now not look up pricing of a product sooner than reviewing and if ...
  • Reliance Jio to offer sharp tariff discounts for customers signing up by March-end
    Reliance Industries' Jio unit will charge a tariff for its services from April, but will offer ...
  • Pentagon strongly condemns North Korea missile test
    The Pentagon on Monday strongly condemned North Korea’s latest missile test, adding that the ...
  • Fitbit Zip 2017 review
    Fitbit PROS: Clever, accurate tracking Expandable online service Integration with 3rd ...
  • Bank wallets growing faster than e-wallets
    In the  bank  versus  e-wallets  sweepstakes,  lenders  have now gained lost ground. As of ...

Random Posts

  • SAVE BIG! on Bus Ticket Booking
    SAVE BIG! on Bus Ticket Booking
    24.02.2018 - 0 Comments
    Promocode: RIDE2GETHER Terms & Conditions: Flat ₹120 Cashback on bus ticket bookings. Offer is…
  • 3 Ways A Romantic Relationship Can Spark Your Spiritual Awakening
    3 Ways A Romantic Relationship Can Spark Your Spiritual Awakening
    07.08.2016 - 0 Comments
    In this post, Shelly Bullard gives us a peek into the way romantic relationships can facilitate real…
  • Yepzon launches tracker devices
    Yepzon launches tracker devices
    22.02.2018 - 0 Comments
    NEW DELHI: With the percentage of heinous crime rates like that of sexual assault, molestation, acid…
  • How to search the full text of web pages in your Chrome browsing history with Falcon
    How to search the full text of web pages in your Chrome browsing history with Falcon
    12.02.2017 - 0 Comments
    Finding a website in your browsing history is easy if you know the title of the webpage or site. But if…
  • Xiaomi Redmi Note 4 sale on Mi.com over, all versions out of stock
    Xiaomi Redmi Note 4 sale on Mi.com over, all versions out of stock
    04.02.2017 - 0 Comments
    Update: Xiaomi Redmi Note 4 sale is now over on Mi.com with all versions of the phone showing…

Labels

Android Apk Files Android Apps Android Games Apps Apk Files Apps Hack Tricks Entertainment Free Internet Freecharge Gadgets Games Apk Files How To's Laptops Guide Mobiles Reviews Technology Viral's android zone free recharge

Entertainment

Tricks

Popular Posts

  • Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Refer & ...
  • Taotronics TT-BH22 Headphones Review
    We make it a ...
  • Hands-on with the home windows 10 Creators update for the Xbox One: Beam recreation streaming arrives
    The Windows ...
  • Pentagon strongly condemns North Korea missile test
    The Pentagon on ...
  • Reliance Jio to offer sharp tariff discounts for customers signing up by March-end
    Reliance Industries' Jio unit will charge a tariff for its services from April, but will offer ...
  • Fitbit Zip 2017 review
    Fitbit PROS ...
  • Bank wallets growing faster than e-wallets
    In the  bank ...

Random Posts

  • How to Fix Annoying Nest Secure Notifications
    How to Fix Annoying Nest Secure Notifications
    27.01.2018 - 0 Comments
    Depending on how you have Nest’s Home/Away Assist feature set up, you might be receiving notifications to…
  • Moto 360 and 360 Sport updated with new Moto Body features and a security update
    Moto 360 and 360 Sport updated with new Moto Body features and a security update
    10.06.2016 - 0 Comments
    A new update, build number MWD49B, has begun heading out to the Moto 360 (2nd Gen) and…
  • POP3 vs. IMAP: Which protocol lets you get all of your email on any device
    POP3 vs. IMAP: Which protocol lets you get all of your email on any device
    12.02.2017 - 0 Comments
    Wayne Zimmerman’s wife usually reads email on her own PC. But when she tries to read it on her husband’s…
  • Freecharge Cashback Offer: Get Rs.20 Cashback On Recharge & Bill Payment of Rs.50
    Freecharge Cashback Offer: Get Rs.20 Cashback On Recharge & Bill Payment of Rs.50
    03.03.2017 - 0 Comments
    Freecharge has come again with an awesome offer.Now You will get Rs 20 cashback on Recharge & Bill…
  • 2vin App Refer And Earn – Earn Free Recharge, Pendrives And More (Rs 10 Per Refer)
    2vin App Refer And Earn – Earn Free Recharge, Pendrives And More (Rs 10 Per Refer)
    06.03.2016 - 0 Comments
    2vin App Refer And Earn Offer – 2vin is a new app which is offering free recharge, power banks, shoes, mobile…

Most Popular

  • Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Refer & ...
  • SAMSUNG GALAXY J7 (2016) REVIEWS
    SAMSUNG GALAXY J7 (2016) REVIEWS
    SAMSUNG GALAXY J ...
  • Top 5 Best SmartPhones under 7000 Rs (March 2017)
    Looking for the ...
  • Apple, IBM, Cisco are huge because of Indians, do not deny them H-1B visa: RBI Governor Urjit Patel
    ...
  • SAMSUNG GALAXY J7 (2016) Specifications
    SAMSUNG GALAXY J ...
  • BlackBerry Teases Marshmallow Beta Testing for Priv by Next Week
    Blackberry ...
  • LG Q6 Review
    LG Q6 Review
    2017 is ...

Contact Form

Name

Email *

Message *

Offers Zone

Created By Android Century Distributed by Android Century
  • Home
  • About us
  • Contact us
  • Privacy policy
  • Terms of use
  • Advertise here
Subscribe Via Email Subscribe To Android Century By Email And Get Free Updates. ;-)


Your email address is safe with us!