Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2017-0663

Опубликовано: 14 июн. 2017
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 6.8
CVSS3: 7.8

Описание

A remote code execution vulnerability in libxml2 could enable an attacker using a specially crafted file to execute arbitrary code within the context of an unprivileged process. This issue is rated as High due to the possibility of remote code execution in an application that uses this library. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37104170.

РелизСтатусПримечание
artful

DNE

bionic

DNE

devel

DNE

esm-apps-legacy/xenial

ignored

abandoned
esm-apps/xenial

ignored

end of ESM support, was ignored [abandoned]
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was ignored [abandoned]]
precise/esm

DNE

trusty

ignored

end of standard support
trusty/esm

DNE

trusty was ignored [abandoned]
upstream

needs-triage

Показывать по

РелизСтатусПримечание
artful

not-affected

2.9.4+dfsg1-3.1
bionic

not-affected

2.9.4+dfsg1-3.1
devel

not-affected

2.9.4+dfsg1-3.1
esm-infra-legacy/trusty

released

2.9.1+dfsg1-3ubuntu4.10
esm-infra-legacy/xenial

released

2.9.3+dfsg1-1ubuntu0.3
esm-infra/bionic

not-affected

2.9.4+dfsg1-3.1
esm-infra/xenial

released

2.9.3+dfsg1-1ubuntu0.3
precise/esm

not-affected

2.7.8.dfsg-5.1ubuntu4.18
trusty

released

2.9.1+dfsg1-3ubuntu4.10
trusty/esm

released

2.9.1+dfsg1-3ubuntu4.10

Показывать по

EPSS

Процентиль: 82%
0.02311
Низкий

6.8 Medium

CVSS2

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
redhat
больше 9 лет назад

A remote code execution vulnerability in libxml2 could enable an attacker using a specially crafted file to execute arbitrary code within the context of an unprivileged process. This issue is rated as High due to the possibility of remote code execution in an application that uses this library. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37104170.

CVSS3: 7.8
nvd
около 9 лет назад

A remote code execution vulnerability in libxml2 could enable an attacker using a specially crafted file to execute arbitrary code within the context of an unprivileged process. This issue is rated as High due to the possibility of remote code execution in an application that uses this library. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37104170.

CVSS3: 7.8
debian
около 9 лет назад

A remote code execution vulnerability in libxml2 could enable an attac ...

CVSS3: 7.8
github
больше 4 лет назад

A remote code execution vulnerability in libxml2 could enable an attacker using a specially crafted file to execute arbitrary code within the context of an unprivileged process. This issue is rated as High due to the possibility of remote code execution in an application that uses this library. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37104170.

suse-cvrf
около 9 лет назад

Security update for libxml2

EPSS

Процентиль: 82%
0.02311
Низкий

6.8 Medium

CVSS2

7.8 High

CVSS3