CVE-2017-0404
published 2017-01-12CVE-2017-0404: An elevation of privilege vulnerability in the kernel sound subsystem could enable a local malicious application to execute arbitrary code within the context…
PriorityP433high7CVSS 3.0
AVLACHPRNUIRSUCHIHAH
EPSS
1.62%
73.4th percentile
An elevation of privilege vulnerability in the kernel sound subsystem could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-32510733.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | — | — |
| android | — | — | |
| google_inc | android | — | — |
| google_inc | android | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
CVSS provenance
nvdv3.07.0HIGHCVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.07.6HIGHAV:N/AC:H/Au:N/C:C/I:C/A:C
vendor_debian7.0LOW
vendor_redhat7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-48pw-mx7j-q7j4: An elevation of privilege vulnerability in the kernel sound subsystem could enable a local malicious application to execute arbitrary code within the
ghsa_unreviewed·2022-05-13
CVE-2017-0404 [HIGH] GHSA-48pw-mx7j-q7j4: An elevation of privilege vulnerability in the kernel sound subsystem could enable a local malicious application to execute arbitrary code within the
An elevation of privilege vulnerability in the kernel sound subsystem could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-32510733.
Red Hat
kernel: Privilege escalation in Android sound subsystem
vendor_redhat·2017-01-01·CVSS 7.0
CVE-2017-0404 [HIGH] kernel: Privilege escalation in Android sound subsystem
kernel: Privilege escalation in Android sound subsystem
An elevation of privilege vulnerability in the kernel sound subsystem could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-32510733.
Statement: This issue did not affect the versions of the Linux kernel as shipped with Red Hat Enterprise Linux, as they did not include support for Android kernel sound subsystem.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise
Android
CVE-2017-0404: Android Security Bulletin 2017-01-01
CVE: CVE-2017-0404
Severity: HIGH
References: A-32510733*
vendor_android·2017-01-01·CVSS 7.0
CVE-2017-0404 [HIGH] CVE-2017-0404: Android Security Bulletin 2017-01-01
CVE: CVE-2017-0404
Severity: HIGH
References: A-32510733*
Android Security Bulletin 2017-01-01
CVE: CVE-2017-0404
Severity: HIGH
References: A-32510733*
Debian
CVE-2017-0404: linux - An elevation of privilege vulnerability in the kernel sound subsystem could enab...
vendor_debian·2017·CVSS 7.0
CVE-2017-0404 [HIGH] CVE-2017-0404: linux - An elevation of privilege vulnerability in the kernel sound subsystem could enab...
An elevation of privilege vulnerability in the kernel sound subsystem could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-32510733.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-2897 libxls: out-of-bounds vulnerability in the read_MSAT function which could result in remote code execution
bugzilla·2020-04-29·CVSS 7.8
CVE-2017-2897 [HIGH] CVE-2017-2897 libxls: out-of-bounds vulnerability in the read_MSAT function which could result in remote code execution
CVE-2017-2897 libxls: out-of-bounds vulnerability in the read_MSAT function which could result in remote code execution
An exploitable out-of-bounds write vulnerability exists in the read_MSAT function of libxls 1.4. A specially crafted XLS file can cause a memory corruption resulting in remote code execution. An attacker can send malicious XLS file to trigger this vulnerability.
Discussion:
External References:
https://talosintelligence.com/vulnerability_reports/TALOS-2017-0404
Bugzilla
CVE-2017-0404 kernel: Privilege escalation in Android sound subsystem
bugzilla·2017-01-31·CVSS 7.0
CVE-2017-0404 [HIGH] CVE-2017-0404 kernel: Privilege escalation in Android sound subsystem
CVE-2017-0404 kernel: Privilege escalation in Android sound subsystem
An elevation of privilege vulnerability in the kernel sound subsystem could enable a local malicious application to execute arbitrary code within the context of the kernel.
Discussion:
Statement:
This issue did not affect the versions of the Linux kernel as shipped with Red Hat Enterprise Linux, as they did not include support for Android kernel sound subsystem.
2017-01-12
Published