SB2017041317 - Improper Neutralization of Special Elements in Output Used by a Downstream Component in Google, Google Android
Published: April 13, 2017 Updated: August 8, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper Neutralization of Special Elements in Output Used by a Downstream Component (CVE-ID: CVE-2016-1155)
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
HTTP header injection vulnerability in the URLConnection class in Android OS 2.2 through 6.0 allows remote attackers to execute arbitrary scripts or set arbitrary values in cookies.
Remediation
Install update from vendor's website.