CVE-2017-0427
published 2017-02-08CVE-2017-0427: An elevation of privilege vulnerability in the kernel file system could enable a local malicious application to execute arbitrary code within the context of…
PriorityP337high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
EPSS
0.98%
58.2th percentile
An elevation of privilege vulnerability in the kernel file system could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-31495866.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | <= 7.1.1 | — | |
| android | — | — | |
| google_inc | android | — | — |
| google_inc | android | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9q8v-89mc-3pg4: An elevation of privilege vulnerability in the kernel file system could enable a local malicious application to execute arbitrary code within the cont
ghsa_unreviewed·2022-05-13
CVE-2017-0427 [HIGH] GHSA-9q8v-89mc-3pg4: An elevation of privilege vulnerability in the kernel file system could enable a local malicious application to execute arbitrary code within the cont
An elevation of privilege vulnerability in the kernel file system could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-31495866.
OSV
CVE-2017-0427: An elevation of privilege vulnerability in the kernel file system could enable a local malicious application to execute arbitrary code within the cont
osv·2017-02-08·CVSS 7.8
CVE-2017-0427 [HIGH] CVE-2017-0427: An elevation of privilege vulnerability in the kernel file system could enable a local malicious application to execute arbitrary code within the cont
An elevation of privilege vulnerability in the kernel file system could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-31495866.
Android
CVE-2017-0427: Android Security Bulletin 2017-02-01
CVE: CVE-2017-0427
Severity: CRITICAL
References: A-31495866*
vendor_android·2017-02-01·CVSS 7.8
CVE-2017-0427 [HIGH] CVE-2017-0427: Android Security Bulletin 2017-02-01
CVE: CVE-2017-0427
Severity: CRITICAL
References: A-31495866*
Android Security Bulletin 2017-02-01
CVE: CVE-2017-0427
Severity: CRITICAL
References: A-31495866*
No detection rules found.
No public exploits indexed.
arXiv
Trusted Container Extensions for Container-based Confidential Computing
arxiv_fulltext·2022-05-11
Trusted Container Extensions for Container-based Confidential Computing
Trusted Container Extensions for Container-based Confidential Computing
draft
[1]
plain
Anonymous
[1]
camera
Ferdinand Brasser, Patrick Jauernig, Frederik Pustelnik,
Ahmad-Reza Sadeghi, Emmanuel Stapf
Technical University of Darmstadt, Germany
\ferdinand.brasser, patrick.jauernig, emmanuel.stapf\@sanctuary.dev
\ahmad.sadeghi\@trust.tu-darmstadt.de
## Abstract
Cloud computing has emerged as a corner stone of today's computing landscape. More and more customers who outsource their infrastructure benefit from the manageability, scalability and cost saving that come with cloud computing. Those benefits get amplified by the trend towards microservices. Instead of renting and maintaining full VMs, customers increasingly leverage container technologies, which come with a much more light
Bugzilla
CVE-2017-2920 libofx: Memory corruption in the .SVG parsing functionality
bugzilla·2017-10-09·CVSS 7.8
CVE-2017-2920 [HIGH] CVE-2017-2920 libofx: Memory corruption in the .SVG parsing functionality
CVE-2017-2920 libofx: Memory corruption in the .SVG parsing functionality
An exploitable buffer overflow vulnerability exists in the tag parsing functionality of LibOFX 0.9.11. A specially crafted OFX file can cause a write out of bounds resulting in a buffer overflow on the stack. An attacker can construct a malicious OFX file to trigger this vulnerability.
External References:
https://www.talosintelligence.com/vulnerability_reports/TALOS-2017-0427
Discussion:
Created libofx tracking bugs for this issue:
Affects: epel-all [bug 1492202]
Affects: fedora-all [bug 1492203]
---
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individua
2017-02-08
Published