CVE-2017-0403
published 2017-01-12CVE-2017-0403: An elevation of privilege vulnerability in the kernel performance subsystem could enable a local malicious application to execute arbitrary code within the…
PriorityP433high7CVSS 3.0
AVLACHPRNUIRSUCHIHAH
EPSS
1.62%
73.4th percentile
An elevation of privilege vulnerability in the kernel performance subsystem could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-32402548.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | — | — |
| android | — | — | |
| google_inc | android | — | — |
| google_inc | android | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
CVSS provenance
nvdv3.07.0HIGHCVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.07.6HIGHAV:N/AC:H/Au:N/C:C/I:C/A:C
vendor_debian7.0LOW
vendor_redhat7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Android
CVE-2017-0403: Android Security Bulletin 2017-01-01
CVE: CVE-2017-0403
Severity: HIGH
References: A-32402548*
vendor_android·2017-01-01·CVSS 7.0
CVE-2017-0403 [HIGH] CVE-2017-0403: Android Security Bulletin 2017-01-01
CVE: CVE-2017-0403
Severity: HIGH
References: A-32402548*
Android Security Bulletin 2017-01-01
CVE: CVE-2017-0403
Severity: HIGH
References: A-32402548*
Red Hat
kernel: Privilege escalation in Android performance subsystem
vendor_redhat·2017-01-01·CVSS 7.0
CVE-2017-0403 [HIGH] kernel: Privilege escalation in Android performance subsystem
kernel: Privilege escalation in Android performance subsystem
An elevation of privilege vulnerability in the kernel performance subsystem could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-32402548.
Statement: This issue did not affect the versions of the Linux kernel as shipped with Red Hat Enterprise Linux, as they did not include support for Android kernel performance subsystem.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (
Debian
CVE-2017-0403: linux - An elevation of privilege vulnerability in the kernel performance subsystem coul...
vendor_debian·2017·CVSS 7.0
CVE-2017-0403 [HIGH] CVE-2017-0403: linux - An elevation of privilege vulnerability in the kernel performance subsystem coul...
An elevation of privilege vulnerability in the kernel performance subsystem could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-32402548.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-2x3v-jgm9-v94x: An elevation of privilege vulnerability in the kernel performance subsystem could enable a local malicious application to execute arbitrary code withi
ghsa_unreviewed·2022-05-13
CVE-2017-0403 [HIGH] GHSA-2x3v-jgm9-v94x: An elevation of privilege vulnerability in the kernel performance subsystem could enable a local malicious application to execute arbitrary code withi
An elevation of privilege vulnerability in the kernel performance subsystem could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-32402548.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-2896 libxls: out-of-bounds write vulnerability exists in the xls_mergedCells function could result in remote code execution
bugzilla·2020-04-29·CVSS 7.8
CVE-2017-2896 [HIGH] CVE-2017-2896 libxls: out-of-bounds write vulnerability exists in the xls_mergedCells function could result in remote code execution
CVE-2017-2896 libxls: out-of-bounds write vulnerability exists in the xls_mergedCells function could result in remote code execution
An exploitable out-of-bounds write vulnerability exists in the xls_mergedCells function of libxls 1.4. . A specially crafted XLS file can cause a memory corruption resulting in remote code execution. An attacker can send malicious XLS file to trigger this vulnerability.
Discussion:
External References:
https://talosintelligence.com/vulnerability_reports/TALOS-2017-0403
Bugzilla
CVE-2017-0403 kernel: Privilege escalation in Android performance subsystem
bugzilla·2017-01-31·CVSS 7.0
CVE-2017-0403 [HIGH] CVE-2017-0403 kernel: Privilege escalation in Android performance subsystem
CVE-2017-0403 kernel: Privilege escalation in Android performance subsystem
An elevation of privilege vulnerability in the kernel performance subsystem could enable a local malicious application to execute arbitrary code within the context of the kernel.
Discussion:
Statement:
This issue did not affect the versions of the Linux kernel as shipped with Red Hat Enterprise Linux, as they did not include support for Android kernel performance subsystem.
2017-01-12
Published