CVE-2017-0336
published 2017-03-08CVE-2017-0336: An information disclosure vulnerability in the NVIDIA GPU driver could enable a local malicious application to access data outside of its permission levels…
PriorityP422medium5.5CVSS 3.0
AVLACLPRNUIRSUCHINAN
EPSS
0.86%
54.5th percentile
An information disclosure vulnerability in the NVIDIA GPU driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as High because it could be used to access sensitive data without explicit user permission. Product: Android. Versions: Kernel-3.18. Android ID: A-33042679. References: N-CVE-2017-0336.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| linux | linux_kernel | — | — |
| nvidia_corporation | android | — | — |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-prfx-wwr9-26vx: An information disclosure vulnerability in the NVIDIA GPU driver could enable a local malicious application to access data outside of its permission l
ghsa_unreviewed·2022-05-17·CVSS 5.5
CVE-2017-0336 [MEDIUM] CWE-200 GHSA-prfx-wwr9-26vx: An information disclosure vulnerability in the NVIDIA GPU driver could enable a local malicious application to access data outside of its permission l
An information disclosure vulnerability in the NVIDIA GPU driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as High because it could be used to access sensitive data without explicit user permission. Product: Android. Versions: Kernel-3.18. Android ID: A-33042679. References: N-CVE-2017-0336.
OSV
CVE-2017-0336: An information disclosure vulnerability in the NVIDIA GPU driver could enable a local malicious application to access data outside of its permission l
osv·2017-03-08·CVSS 5.5
CVE-2017-0336 [MEDIUM] CVE-2017-0336: An information disclosure vulnerability in the NVIDIA GPU driver could enable a local malicious application to access data outside of its permission l
An information disclosure vulnerability in the NVIDIA GPU driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as High because it could be used to access sensitive data without explicit user permission. Product: Android. Versions: Kernel-3.18. Android ID: A-33042679. References: N-CVE-2017-0336.
Android
CVE-2017-0336: Android Security Bulletin 2017-03-01
CVE: CVE-2017-0336
Severity: HIGH
References: A-33042679*
N-CVE-2017-0336
vendor_android·2017-03-01·CVSS 5.5
CVE-2017-0336 [MEDIUM] CVE-2017-0336: Android Security Bulletin 2017-03-01
CVE: CVE-2017-0336
Severity: HIGH
References: A-33042679*
N-CVE-2017-0336
Android Security Bulletin 2017-03-01
CVE: CVE-2017-0336
Severity: HIGH
References: A-33042679*
N-CVE-2017-0336
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-2672 foreman: Image password leak
bugzilla·2017-04-06·CVSS 6.5
CVE-2017-2672 [MEDIUM] CVE-2017-2672 foreman: Image password leak
CVE-2017-2672 foreman: Image password leak
When images for compute resources (e.g. an OpenStack image) are added/registered in Foreman, the password used to log in is recorded in plain text in the audit log. This may allow users with access to view the audit log to access newly provisioned hosts using the stored credentials.
Upstream bug:
http://projects.theforeman.org/issues/19169
Discussion:
This issue has been addressed in the following products:
Red Hat Satellite 6.3 for RHEL 7
Via RHSA-2018:0336 https://access.redhat.com/errata/RHSA-2018:0336
Bugzilla
CVE-2017-2667 rubygem-hammer_cli: no verification of API server's SSL certificate
bugzilla·2017-03-27·CVSS 8.1
CVE-2017-2667 [HIGH] CVE-2017-2667 rubygem-hammer_cli: no verification of API server's SSL certificate
CVE-2017-2667 rubygem-hammer_cli: no verification of API server's SSL certificate
Tomas Strachota of Red Hat reports:
It was found that Hammer CLI, a CLI utility for Foreman, did not explicitly set the verify_ssl flag for apipie-bindings that disable it by default. As a result the server certificates are not checked and connections are prone to man-in-the-middle attacks.
Upstream issue:
http://projects.theforeman.org/issues/19033
Discussion:
Acknowledgments:
Name: Tomas Strachota (Red Hat)
---
openstack 6 foreman installer is EOL
---
This issue has been addressed in the following products:
Red Hat Satellite 6.3 for RHEL 7
Via RHSA-2018:0336 https://access.redhat.com/errata/RHSA-2018:0336
---
Statement:
This issue affects the versions of rubygem-hammer_cli as shipped with Re
2017-03-08
Published