Google hat den Sicherheitspatch für den Monat Juli veröffentlicht. Diesmal gibt es eine wichtige Neuerung. Fleißig am Updates verteilen sind auch BlackBerry, Samsung sowie LG.
Wie gewohnt hat Google zum Monatsanfang ein neues Sicherheitsupdate für das Android-Betriebssystem freigegeben. Besitzer eines Nexus-Smartphones oder Tablets können entweder auf das Over-the-Air-Update warten oder die nötigen OTA-Dateien oder Factory Images herunterladen und manuell auf den Geräten installieren.
Insgesamt bereinigt Google 54 Sicherheitslücken. Es gibt allerdings eine wichtige Neuerung, denn in diesem Monat erscheint das Juli-Update mit zwei Security-Patch-Level. Das erste ist datiert auf den 1. Juli 2016 und eliminiert Schwachstellen, die in Verbindung mit dem reinen Android-System stehen. Es konnten 2 als kritisch, 11 als hoch und 9 als moderat eingestufte Lücken geschlossen werden. Das Patch-Paket vom 5. Juli 2016 stopft 7 kritisch, 18 hoch und 7 moderat eingestufte Lücken, die gerätespezifische Treiber für unter anderem WLAN, Grafik, USB und Kamera von Herstellern wie Qualcomm, MediaTek und Nvidia betreffen.
Android-Sicherheitspatch-Ebene 1. Juli 2016:
| Issue | CVE | Severity | Affects Nexus? |
| Remote code execution vulnerability in Mediaserver | CVE-2016-2506, CVE-2016-2505, CVE-2016-2507, CVE-2016-2508, CVE-2016-3741, CVE-2016-3742, CVE-2016-3743 |
Critical | Yes |
| Remote code execution vulnerability in OpenSSL & BoringSSL | CVE-2016-2108 | Critical | Yes |
| Remote code execution vulnerability in Bluetooth | CVE-2016-3744 | High | Yes |
| Elevation of privilege vulnerability in libpng | CVE-2016-3751 | High | Yes |
| Elevation of privilege vulnerability in Mediaserver | CVE-2016-3745, CVE-2016-3746, CVE-2016-3747 |
High | Yes |
| Elevation of privilege vulnerability in sockets | CVE-2016-3748 | High | Yes |
| Elevation of privilege vulnerability in LockSettingsService | CVE-2016-3749 | High | Yes |
| Elevation of privilege vulnerability in Framework APIs | CVE-2016-3750 | High | Yes |
| Elevation of privilege vulnerability in ChooserTarget service | CVE-2016-3752 | High | Yes |
| Information disclosure vulnerability in Mediaserver | CVE-2016-3753 | High | No* |
| Information disclosure vulnerability in OpenSSL | CVE-2016-2107 | High | No* |
| Denial of service vulnerability in Mediaserver | CVE-2016-3754, CVE-2016-3755, CVE-2016-3756 |
High | Yes |
| Denial of service vulnerability in libc | CVE-2016-3818 | High | No* |
| Elevation of privilege vulnerability in lsof | CVE-2016-3757 | Moderate | Yes |
| Elevation of privilege vulnerability in DexClassLoader | CVE-2016-3758 | Moderate | Yes |
| Elevation of privilege vulnerability in Framework APIs | CVE-2016-3759 | Moderate | Yes |
| Elevation of privilege vulnerability in Bluetooth | CVE-2016-3760 | Moderate | Yes |
| Elevation of privilege vulnerability in NFC | CVE-2016-3761 | Moderate | Yes |
| Elevation of privilege vulnerability in sockets | CVE-2016-3762 | Moderate | Yes |
| Information disclosure vulnerability in Proxy Auto-Config | CVE-2016-3763 | Moderate | Yes |
| Information disclosure vulnerability in Mediaserver | CVE-2016-3764, CVE-2016-3765 |
Moderate | Yes |
| Denial of service vulnerability in Mediaserver | CVE-2016-3766 | Moderate | Yes |
* Supported Nexus devices that have installed all available updates are not affected by this vulnerability.
Android-Sicherheitspatch-Ebene 5. Juli 2016:
| Issue | CVE | Severity | Affects Nexus? |
| Elevation of privilege vulnerability in Qualcomm GPU driver (Device specific) | CVE-2016-2503, CVE-2016-2067 |
Critical | Yes |
| Elevation of privilege vulnerability in MediaTek Wi-Fi driver (Device specific) | CVE-2016-3767 | Critical | Yes |
| Elevation of privilege vulnerability in Qualcomm performance component (Device specific) | CVE-2016-3768 | Critical | Yes |
| Elevation of privilege vulnerability in NVIDIA video driver (Device specific) | CVE-2016-3769 | Critical | Yes |
| Elevation of privilege vulnerability in MediaTek drivers (Device specific) | CVE-2016-3770, CVE-2016-3771, CVE-2016-3772, CVE-2016-3773, CVE-2016-3774 |
Critical | Yes |
| Elevation of privilege vulnerability in kernel file system (Device specific) | CVE-2016-3775 | Critical | Yes |
| Elevation of privilege vulnerability in USB driver (Device specific) | CVE-2015-8816 | Critical | Yes |
| Elevation of privilege vulnerability in Qualcomm components (Device specific) | CVE-2014-9794, CVE-2014-9795, CVE-2015-8892, CVE-2013-7457, CVE-2014-9781, CVE-2014-9786, CVE-2014-9788, CVE-2014-9779, CVE-2014-9780, CVE-2014-9789, CVE-2014-9793, CVE-2014-9782, CVE-2014-9783, CVE-2014-9785, CVE-2014-9787, CVE-2014-9784, CVE-2014-9777, CVE-2014-9778, CVE-2014-9790, CVE-2014-9792, CVE-2014-9797, CVE-2014-9791, CVE-2014-9796, CVE-2014-9800, CVE-2014-9799, CVE-2014-9801, CVE-2014-9802, CVE-2015-8891, CVE-2015-8888, CVE-2015-8889, CVE-2015-8890 |
High | Yes |
| Elevation of privilege vulnerability in Qualcomm USB driver (Device specific) | CVE-2016-2502 | High | Yes |
| Elevation of privilege vulnerability in Qualcomm Wi-Fi driver (Device specific) | CVE-2016-3792 | High | Yes |
| Elevation of privilege vulnerability in Qualcomm camera driver (Device specific) | CVE-2016-2501 | High | Yes |
| Elevation of privilege vulnerability in NVIDIA camera driver (Device specific) | CVE-2016-3793, CVE-2016-3794 |
High | Yes |
| Elevation of privilege vulnerability in MediaTek power driver (Device specific) | CVE-2016-3795, CVE-2016-3796 |
High | Yes |
| Elevation of privilege vulnerability in Qualcomm Wi-Fi driver (Device specific) | CVE-2016-3797 | High | Yes |
| Elevation of privilege vulnerability in MediaTek hardware sensor driver (Device specific) | CVE-2016-3798 | High | Yes |
| Elevation of privilege vulnerability in MediaTek video driver (Device specific) | CVE-2016-3799, CVE-2016-3800 |
High | Yes |
| Elevation of privilege vulnerability in MediaTek GPS driver (Device specific) | CVE-2016-3801 | High | Yes |
| Elevation of privilege vulnerability in kernel file system (Device specific) | CVE-2016-3802, CVE-2016-3803 |
High | Yes |
| Elevation of privilege vulnerability in MediaTek power management driver (Device specific) | CVE-2016-3804, CVE-2016-3805 |
High | Yes |
| Elevation of privilege vulnerability in MediaTek display driver (Device specific) | CVE-2016-3806 | High | Yes |
| Elevation of privilege vulnerability in serial peripheral interface driver (Device specific) | CVE-2016-3807, CVE-2016-3808 |
High | Yes |
| Elevation of privilege vulnerability in Qualcomm sound driver (Device specific) | CVE-2016-2068 | High | Yes |
| Elevation of privilege vulnerability in kernel (Device specific) | CVE-2014-9803 | High | Yes |
| Information disclosure vulnerability in networking component (Device specific) | CVE-2016-3809 | High | Yes |
| Information disclosure vulnerability in MediaTek Wi-Fi driver (Device specific) | CVE-2016-3810 | High | Yes |
| Elevation of privilege vulnerability in kernel video driver (Device specific) | CVE-2016-3811 | Moderate | Yes |
| Information disclosure vulnerability in MediaTek video codec driver (Device specific) | CVE-2016-3812 | Moderate | Yes |
| Information disclosure vulnerability in Qualcomm USB driver (Device specific) | CVE-2016-3813 | Moderate | Yes |
| Information disclosure vulnerability in NVIDIA camera driver (Device specific) | CVE-2016-3814, CVE-2016-3815 |
Moderate | Yes |
| Information disclosure vulnerability in MediaTek display driver (Device specific) | CVE-2016-3816 | Moderate | Yes |
| Information disclosure vulnerability in kernel teletype driver (Device specific) | CVE-2016-0723 | Moderate | Yes |
| Denial of service vulnerability in Qualcomm bootloader (Device specific) | CVE-2014-9798, CVE-2015-8893 |
Moderate | Yes |
BlackBerry, Samsung & LG
Auf der eigenen Support-Seite hat BlackBerry mitgeteilt, dass den Nutzern das Sicherheitsupdate vom 5. Juli 2016 zur Verfügung gestellt wird. Im Mobile Security Blog von Samsung findet das Juli-Update ebenfalls Erwähnung. Zusätzlich zu den Google-Patches legt Samsung 4 eigene Patches obendrauf, die die Android-Versionen ab 4.4 KitKat, über 5.0/5.1 Lollipop bis 6.0 Marshmallow betreffen und als hoch bzw. moderat eingestuft werden. Überraschenderweise ist Samsung schon seit einigen Tagen dabei, das neue Update mit dem Patch-Level vom 1. Juli 2016 an ausgewählte Top-Modelle zu verteilen. Auch LG hat sich zu Wort gemeldet und sich zum Juli-Update geäußert. Das Unternehmen hat angekündigt das Update mit dem Patch-Level vom 1. Juli 2016 inklusive 2 LG-Patches an die Nutzer zu verteilen. In den Einstellungen unter den Geräteinformationen könnt ihr nachschauen, welche Sicherheitspatch-Ebene auf eurem Gerät installiert ist.
(via)