CVE-2017-0489
published 2017-03-08CVE-2017-0489: An elevation of privilege vulnerability in Location Manager could enable a local malicious application to bypass operating system protections for location…
PriorityP421medium5.5CVSS 3.0
AVLACLPRNUIRSUCNIHAN
EPSS
0.39%
31.4th percentile
An elevation of privilege vulnerability in Location Manager could enable a local malicious application to bypass operating system protections for location data. This issue is rated as Moderate because it could be used to generate inaccurate data. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-33091107.
Affected
36 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3v4f-v37f-fqg3: An elevation of privilege vulnerability in Location Manager could enable a local malicious application to bypass operating system protections for loca
ghsa_unreviewed·2022-05-13
CVE-2017-0489 [MEDIUM] GHSA-3v4f-v37f-fqg3: An elevation of privilege vulnerability in Location Manager could enable a local malicious application to bypass operating system protections for loca
An elevation of privilege vulnerability in Location Manager could enable a local malicious application to bypass operating system protections for location data. This issue is rated as Moderate because it could be used to generate inaccurate data. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-33091107.
OSV
CVE-2017-0489: An elevation of privilege vulnerability in Location Manager could enable a local malicious application to bypass operating system protections for loca
osv·2017-03-08·CVSS 5.5
CVE-2017-0489 [MEDIUM] CVE-2017-0489: An elevation of privilege vulnerability in Location Manager could enable a local malicious application to bypass operating system protections for loca
An elevation of privilege vulnerability in Location Manager could enable a local malicious application to bypass operating system protections for location data. This issue is rated as Moderate because it could be used to generate inaccurate data. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-33091107.
Android
CVE-2017-0489: Android Security Bulletin 2017-03-01
CVE: CVE-2017-0489
Severity: MEDIUM
Affected AOSP versions: 4
vendor_android·2017-03-01·CVSS 5.5
CVE-2017-0489 [MEDIUM] CVE-2017-0489: Android Security Bulletin 2017-03-01
CVE: CVE-2017-0489
Severity: MEDIUM
Affected AOSP versions: 4
Android Security Bulletin 2017-03-01
CVE: CVE-2017-0489
Severity: MEDIUM
Affected AOSP versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1
References: A-33091107
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-15137 atomic-openshift: image import whitelist can be bypassed by creating an imagestream or using oc tag
bugzilla·2018-04-11·CVSS 4.3
CVE-2017-15137 [MEDIUM] CVE-2017-15137 atomic-openshift: image import whitelist can be bypassed by creating an imagestream or using oc tag
CVE-2017-15137 atomic-openshift: image import whitelist can be bypassed by creating an imagestream or using oc tag
The image import whitelist is enforced when running "oc import-image someregistry.com/someimage"
but the whitelist is not enforced when running
"oc tag someregistry.com:foo some:tag"
nor is it enforced when directly creating an imagestream tag that references a non-whitelisted registry.
Discussion:
Acknowledgments:
Name: Ben Parees (Red Hat)
---
This was fixed in the release of OpenShift 3.9 via RHBA-2018:0489
---
Is OpenShift 3.7 affected as well?
---
Dominik: Yes, Would you like to request a backport of this issue? It is only rated moderate so please provide the reason while you require it.
---
Thanks for confirmation, Jason. Please have the corresponding secur
Bugzilla
CVE-2017-15138 atomic-openshift: cluster-reader can escalate to creating builds via webhooks in any project
bugzilla·2018-04-11·CVSS 5.0
CVE-2017-15138 [MEDIUM] CVE-2017-15138 atomic-openshift: cluster-reader can escalate to creating builds via webhooks in any project
CVE-2017-15138 atomic-openshift: cluster-reader can escalate to creating builds via webhooks in any project
It is reported that as a result of cluster-reader having view access on all builds in all projects, the cluster reader is able to escalate to also create builds in all projects since they have access to the secret key for the webhook.
A project viewer has the same ability to escalate but is obviously scoped to the single project.
The main problem is that we have confidential information (webhook tokens) that lives in a non-confidential resource.
Discussion:
Acknowledgments:
Name: Jessica Forrester (Red Hat)
---
This was fixed in the release of OpenShift 3.9 via RHBA-2018:0489
---
Are 3.2 and 3.7 affected as well?
---
This issue also affects all OCP 3.x versions prior to 3
Bugzilla
CVE-2017-14440 SDL2_image: code execution in the ILBM image rendering
bugzilla·2018-03-06·CVSS 8.8
CVE-2017-14440 [HIGH] CVE-2017-14440 SDL2_image: code execution in the ILBM image rendering
CVE-2017-14440 SDL2_image: code execution in the ILBM image rendering
A flaw was found in Simple DirectMedia Layer. An exploitable code execution vulnerability exists in the ILBM image rendering functionality of SDL2_image-2.0.2. A specially crafted ILBM image can cause a stack overflow resulting in code execution. An attacker can display a specially crafted image to trigger this vulnerability.
References:
https://www.talosintelligence.com/vulnerability_reports/TALOS-2017-0489
Discussion:
Created SDL2_image tracking bugs for this issue:
Affects: fedora-all [bug 1552173]
Affects: epel-7 [bug 1552172]
---
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs
http://www.securityfocus.com/bid/96792http://www.securitytracker.com/id/1037968https://source.android.com/security/bulletin/2017-03-01https://source.android.com/security/bulletin/2017-03-01.htmlhttp://www.securityfocus.com/bid/96792http://www.securitytracker.com/id/1037968https://source.android.com/security/bulletin/2017-03-01
2017-03-08
Published