OSDN Git Service

Bump Security Patch Level to 2018-12-05
authorVasyl Gello <vasek.gello@gmail.com>
Tue, 4 Dec 2018 17:09:21 +0000 (19:09 +0200)
committerVasyl Gello <vasek.gello@gmail.com>
Tue, 18 Dec 2018 09:38:17 +0000 (11:38 +0200)
Implemented:
============

CVE-2018-9549   A-112160868     RCE     Critical        7.0, 7.1.1, 7.1.2, 8.0, 8.1, 9
CVE-2018-9555   A-112321180     RCE     Critical        7.0, 7.1.1, 7.1.2, 8.0, 8.1, 9
CVE-2018-9556   A-113118184     RCE     Critical        9
CVE-2018-9552   A-113260892     ID      Critical        7.0, 7.1.1, 7.1.2, 8.0, 8.1, 9
CVE-2018-9553   A-116615297     RCE     High            7.0, 7.1.1, 7.1.2, 8.0, 8.1, 9
CVE-2018-9558   A-112161557     EoP     High            7.0, 7.1.1, 7.1.2, 8.0, 8.1, 9
CVE-2018-9559   A-112731440     EoP     High            7.0, 7.1.1, 7.1.2, 8.0, 8.1, 9
CVE-2018-9548   A-112555574     ID      High            7.0, 7.1.1, 7.1.2, 8.0, 8.1, 9
CVE-2018-9554   A-114770654     ID      High            7.0, 7.1.1, 7.1.2, 8.0, 8.1
CVE-2018-9566   A-74249842      ID      High            7.0, 7.1.1, 7.1.2, 8.0, 8.1, 9

Not implemented:
============

CVE-2018-9557   A-35385357      EoP     High            7.0, 7.1.1, 7.1.2

No impact:
============

CVE-2018-9550   A-112660981     RCE     Critical        9
CVE-2018-9551   A-112891548     RCE     Critical        9
CVE-2018-9538   A-112181526     EoP     High            8.1, 9
CVE-2018-9547   A-114223584     EoP     High            8.1, 9
CVE-2018-9560   A-79946737      EoP     High            9
CVE-2018-9562   A-113164621     ID      High            9

Change-Id: I2ee87fe456d088d2fc19fb37a00ac377694078ad
Signed-off-by: Vasyl Gello <vasek.gello@gmail.com>
core/version_defaults.mk

index 8b7703c..a908f7d 100644 (file)
@@ -131,7 +131,7 @@ ifeq "" "$(PLATFORM_SECURITY_PATCH)"
     #  It must be of the form "YYYY-MM-DD" on production devices.
     #  It must match one of the Android Security Patch Level strings of the Public Security Bulletins.
     #  If there is no $PLATFORM_SECURITY_PATCH set, keep it empty.
-    PLATFORM_SECURITY_PATCH := 2018-11-05
+    PLATFORM_SECURITY_PATCH := 2018-12-05
 endif
 
 ifeq "" "$(PLATFORM_BASE_OS)"