Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-0386

Опубликовано: 01 дек. 2016
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

An elevation of privilege vulnerability in the libnl library could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1. Android ID: A-32255299.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5libnlNot affected
Red Hat Enterprise Linux 6libnlNot affected
Red Hat Enterprise Linux 6libnl3Not affected
Red Hat Enterprise Linux 7libnlNot affected
Red Hat Enterprise Linux 7libnl3Not affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=1414304libnl: Privilege escalation due to insufficient data checks in nla_reserve and nla_put

EPSS

Процентиль: 34%
0.00138
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
nvd
около 9 лет назад

An elevation of privilege vulnerability in the libnl library could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1. Android ID: A-32255299.

CVSS3: 7.8
debian
около 9 лет назад

An elevation of privilege vulnerability in the libnl library could ena ...

suse-cvrf
больше 3 лет назад

Security update for libnl3

suse-cvrf
больше 3 лет назад

Security update for libnl-1_1

CVSS3: 7.8
github
больше 3 лет назад

An elevation of privilege vulnerability in the libnl library could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1. Android ID: A-32255299.

EPSS

Процентиль: 34%
0.00138
Низкий

7.8 High

CVSS3