CVE-2017-0499
published 2017-03-08CVE-2017-0499: A denial of service vulnerability in Audioserver could enable a local malicious application to cause a device hang or reboot. This issue is rated as Low due to…
PriorityP415medium5.5CVSS 3.0
AVLACLPRNUIRSUCNINAH
EPSS
0.42%
33.8th percentile
A denial of service vulnerability in Audioserver could enable a local malicious application to cause a device hang or reboot. This issue is rated as Low due to the possibility of a temporary denial of service. Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-32095713.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| flac_project | flac | >= 0 < 1.3.2-1ubuntu0.1 | 1.3.2-1ubuntu0.1 |
| flac_project | flac | >= 0 < 1.3.3-1ubuntu0.1 | 1.3.3-1ubuntu0.1 |
| flac_project | flac | >= 0 < 1.3.3-2ubuntu0.1 | 1.3.3-2ubuntu0.1 |
| flac_project | flac | >= 0 < 1.3.0-2ubuntu0.14.04.1+esm1 | 1.3.0-2ubuntu0.14.04.1+esm1 |
| flac_project | flac | >= 0 < 1.3.1-4ubuntu0.1~esm1 | 1.3.1-4ubuntu0.1~esm1 |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| google_inc | android | — | — |
| google_inc | android | — | — |
| google_inc | android | — | — |
| google_inc | android | — | — |
| google_inc | android | — | — |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.07.1HIGHAV:N/AC:M/Au:N/C:N/I:N/A:C
osv5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Android
CVE-2017-0499: Android Security Bulletin 2017-03-01
CVE: CVE-2017-0499
Severity: LOW
Affected AOSP versions: 5
vendor_android·2017-03-01·CVSS 5.5
CVE-2017-0499 [MEDIUM] CVE-2017-0499: Android Security Bulletin 2017-03-01
CVE: CVE-2017-0499
Severity: LOW
Affected AOSP versions: 5
Android Security Bulletin 2017-03-01
CVE: CVE-2017-0499
Severity: LOW
Affected AOSP versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1
References: A-32095713
OSV
flac vulnerabilities
osv·2022-11-21·CVSS 5.5
CVE-2017-6888 flac vulnerabilities
flac vulnerabilities
It was discovered that FLAC was not properly performing memory management
operations, which could result in a memory leak. An attacker could possibly
use this issue to cause FLAC to consume resources, leading to a denial of
service. This issue only affected Ubuntu 14.04 ESM, Ubuntu 16.04 ESM and
Ubuntu 18.04 LTS. (CVE-2017-6888)
It was discovered that FLAC was not properly performing bounds checking
operations when decoding data. If a user or automated system were tricked
into processing a specially crafted file, an attacker could possibly use
this issue to expose sensitive information or to cause FLAC to crash,
leading to a denial of service. This issue only affected Ubuntu 14.04 ESM,
Ubuntu 16.04 ESM, Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2020-0499)
It was d
GHSA
GHSA-87g7-2h8c-64r2: A denial of service vulnerability in Audioserver could enable a local malicious application to cause a device hang or reboot
ghsa_unreviewed·2022-05-17
CVE-2017-0499 [HIGH] CWE-20 GHSA-87g7-2h8c-64r2: A denial of service vulnerability in Audioserver could enable a local malicious application to cause a device hang or reboot
A denial of service vulnerability in Audioserver could enable a local malicious application to cause a device hang or reboot. This issue is rated as Low due to the possibility of a temporary denial of service. Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-32095713.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-14450 SDL2_image: buffer overflow in the GIF image parsing
bugzilla·2018-03-06·CVSS 7.1
CVE-2017-14450 [HIGH] CVE-2017-14450 SDL2_image: buffer overflow in the GIF image parsing
CVE-2017-14450 SDL2_image: buffer overflow in the GIF image parsing
A flaw was found in Simple DirectMedia Layer. A buffer overflow vulnerability exists in the GIF image parsing functionality of SDL2_image-2.0.2. A specially crafted GIF image can lead to a buffer overflow on a global section. An attacker can display an image to trigger this vulnerability.
References:
https://www.talosintelligence.com/vulnerability_reports/TALOS-2017-0499
Discussion:
Created SDL2_image tracking bugs for this issue:
Affects: fedora-all [bug 1552190]
Affects: epel-7 [bug 1552191]
---
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual communit
Bugzilla
CVE-2017-5039 chromium-browser: use after free in pdfium
bugzilla·2017-03-10·CVSS 7.8
CVE-2017-5039 [HIGH] CVE-2017-5039 chromium-browser: use after free in pdfium
CVE-2017-5039 chromium-browser: use after free in pdfium
An use after free flaw was found in the PDFium component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=679649
External References:
https://chromereleases.googleblog.com/2017/03/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: fedora-all [bug 1431051]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2017:0499 https://rhn.redhat.com/errata/RHSA-2017-0499.html
Bugzilla
CVE-2017-5038 chromium-browser: use after free in guestview
bugzilla·2017-03-10·CVSS 6.3
CVE-2017-5038 [MEDIUM] CVE-2017-5038 chromium-browser: use after free in guestview
CVE-2017-5038 chromium-browser: use after free in guestview
An use after free flaw was found in the GuestView component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=695476
External References:
https://chromereleases.googleblog.com/2017/03/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: fedora-all [bug 1431051]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2017:0499 https://rhn.redhat.com/errata/RHSA-2017-0499.html
Bugzilla
CVE-2017-5040 chromium-browser: information disclosure in v8
bugzilla·2017-03-10·CVSS 4.3
CVE-2017-5040 [MEDIUM] CVE-2017-5040 chromium-browser: information disclosure in v8
CVE-2017-5040 chromium-browser: information disclosure in v8
An information disclosure flaw was found in the V8 component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=691323
External References:
https://chromereleases.googleblog.com/2017/03/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: fedora-all [bug 1431051]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2017:0499 https://rhn.redhat.com/errata/RHSA-2017-0499.html
Bugzilla
CVE-2017-5032 chromium-browser: out of bounds write in pdfium
bugzilla·2017-03-10·CVSS 8.8
CVE-2017-5032 [HIGH] CVE-2017-5032 chromium-browser: out of bounds write in pdfium
CVE-2017-5032 chromium-browser: out of bounds write in pdfium
An out of bounds write flaw was found in the PDFium component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=668724
External References:
https://chromereleases.googleblog.com/2017/03/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: fedora-all [bug 1431051]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2017:0499 https://rhn.redhat.com/errata/RHSA-2017-0499.html
Bugzilla
CVE-2017-5037 CVE-2017-5047 CVE-2017-5048 CVE-2017-5049 CVE-2017-5050 CVE-2017-5051 chromium-browser: multiple out of bounds writes in chunkdemuxer
bugzilla·2017-03-10·CVSS 7.8
CVE-2017-5037 [HIGH] CVE-2017-5037 CVE-2017-5047 CVE-2017-5048 CVE-2017-5049 CVE-2017-5050 CVE-2017-5051 chromium-browser: multiple out of bounds writes in chunkdemuxer
CVE-2017-5037 CVE-2017-5047 CVE-2017-5048 CVE-2017-5049 CVE-2017-5050 CVE-2017-5051 chromium-browser: multiple out of bounds writes in chunkdemuxer
A multiple out of bounds writes flaw was found in the ChunkDemuxer component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=679640
External References:
https://chromereleases.googleblog.com/2017/03/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: fedora-all [bug 1431051]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2017:0499 https://rhn.redhat.com/errata/RHSA-2017-0499.html
Bugzilla
CVE-2017-5035 chromium-browser: incorrect security ui in omnibox
bugzilla·2017-03-10·CVSS 8.1
CVE-2017-5035 [HIGH] CVE-2017-5035 chromium-browser: incorrect security ui in omnibox
CVE-2017-5035 chromium-browser: incorrect security ui in omnibox
An incorrect security ui flaw was found in the Omnibox component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=688425
External References:
https://chromereleases.googleblog.com/2017/03/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: fedora-all [bug 1431051]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2017:0499 https://rhn.redhat.com/errata/RHSA-2017-0499.html
Bugzilla
CVE-2017-5045 chromium-browser: information disclosure in xss auditor
bugzilla·2017-03-10·CVSS 6.1
CVE-2017-5045 [MEDIUM] CVE-2017-5045 chromium-browser: information disclosure in xss auditor
CVE-2017-5045 chromium-browser: information disclosure in xss auditor
An information disclosure flaw was found in the XSS Auditor component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=667079
External References:
https://chromereleases.googleblog.com/2017/03/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: fedora-all [bug 1431051]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2017:0499 https://rhn.redhat.com/errata/RHSA-2017-0499.html
Bugzilla
CVE-2017-5036 chromium-browser: use after free in pdfium
bugzilla·2017-03-10·CVSS 7.8
CVE-2017-5036 [HIGH] CVE-2017-5036 chromium-browser: use after free in pdfium
CVE-2017-5036 chromium-browser: use after free in pdfium
An use after free flaw was found in the PDFium component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=691371
External References:
https://chromereleases.googleblog.com/2017/03/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: fedora-all [bug 1431051]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2017:0499 https://rhn.redhat.com/errata/RHSA-2017-0499.html
Bugzilla
CVE-2017-5044 chromium-browser: heap overflow in skia
bugzilla·2017-03-10·CVSS 6.3
CVE-2017-5044 [MEDIUM] CVE-2017-5044 chromium-browser: heap overflow in skia
CVE-2017-5044 chromium-browser: heap overflow in skia
A heap overflow flaw was found in the Skia component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=688987
External References:
https://chromereleases.googleblog.com/2017/03/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: fedora-all [bug 1431051]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2017:0499 https://rhn.redhat.com/errata/RHSA-2017-0499.html
Bugzilla
CVE-2017-5031 chromium-browser: use after free in angle
bugzilla·2017-03-10·CVSS 8.8
CVE-2017-5031 [HIGH] CVE-2017-5031 chromium-browser: use after free in angle
CVE-2017-5031 chromium-browser: use after free in angle
An use after free flaw was found in the ANGLE component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=682020
External References:
https://chromereleases.googleblog.com/2017/03/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: fedora-all [bug 1431051]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2017:0499 https://rhn.redhat.com/errata/RHSA-2017-0499.html
Bugzilla
CVE-2017-5030 chromium-browser: memory corruption in v8
bugzilla·2017-03-10·CVSS 8.8
CVE-2017-5030 [HIGH] CVE-2017-5030 chromium-browser: memory corruption in v8
CVE-2017-5030 chromium-browser: memory corruption in v8
A memory corruption flaw was found in the V8 component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=682194
External References:
https://chromereleases.googleblog.com/2017/03/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: fedora-all [bug 1431051]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2017:0499 https://rhn.redhat.com/errata/RHSA-2017-0499.html
Bugzilla
CVE-2017-5034 chromium-browser: use after free in pdfium
bugzilla·2017-03-10·CVSS 8.8
CVE-2017-5034 [HIGH] CVE-2017-5034 chromium-browser: use after free in pdfium
CVE-2017-5034 chromium-browser: use after free in pdfium
An use after free flaw was found in the PDFium component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=678461
External References:
https://chromereleases.googleblog.com/2017/03/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: fedora-all [bug 1431051]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2017:0499 https://rhn.redhat.com/errata/RHSA-2017-0499.html
Bugzilla
CVE-2017-5046 chromium-browser: information disclosure in blink
bugzilla·2017-03-10·CVSS 4.3
CVE-2017-5046 [MEDIUM] CVE-2017-5046 chromium-browser: information disclosure in blink
CVE-2017-5046 chromium-browser: information disclosure in blink
An information disclosure flaw was found in the Blink component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=680409
External References:
https://chromereleases.googleblog.com/2017/03/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: fedora-all [bug 1431051]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2017:0499 https://rhn.redhat.com/errata/RHSA-2017-0499.html
Bugzilla
CVE-2017-5029 chromium-browser: integer overflow in libxslt
bugzilla·2017-03-10·CVSS 8.8
CVE-2017-5029 [HIGH] CVE-2017-5029 chromium-browser: integer overflow in libxslt
CVE-2017-5029 chromium-browser: integer overflow in libxslt
An integer overflow flaw was found in the libxslt component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=676623
External References:
https://chromereleases.googleblog.com/2017/03/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: fedora-all [bug 1431051]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2017:0499 https://rhn.redhat.com/errata/RHSA-2017-0499.html
Bugzilla
CVE-2017-5041 chromium-browser: address spoofing in omnibox
bugzilla·2017-03-10·CVSS 4.3
CVE-2017-5041 [MEDIUM] CVE-2017-5041 chromium-browser: address spoofing in omnibox
CVE-2017-5041 chromium-browser: address spoofing in omnibox
An address spoofing flaw was found in the Omnibox component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=642490
External References:
https://chromereleases.googleblog.com/2017/03/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: fedora-all [bug 1431051]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2017:0499 https://rhn.redhat.com/errata/RHSA-2017-0499.html
Bugzilla
CVE-2017-5033 chromium-browser: bypass of content security policy in blink
bugzilla·2017-03-10·CVSS 4.3
CVE-2017-5033 [MEDIUM] CVE-2017-5033 chromium-browser: bypass of content security policy in blink
CVE-2017-5033 chromium-browser: bypass of content security policy in blink
A bypass of content security policy flaw was found in the Blink component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=669086
External References:
https://chromereleases.googleblog.com/2017/03/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: fedora-all [bug 1431051]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2017:0499 https://rhn.redhat.com/errata/RHSA-2017-0499.html
Bugzilla
CVE-2017-5042 chromium-browser: incorrect handling of cookies in cast
bugzilla·2017-03-10·CVSS 5.7
CVE-2017-5042 [MEDIUM] CVE-2017-5042 chromium-browser: incorrect handling of cookies in cast
CVE-2017-5042 chromium-browser: incorrect handling of cookies in cast
An incorrect handling of cookies flaw was found in the Cast component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=671932
External References:
https://chromereleases.googleblog.com/2017/03/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: fedora-all [bug 1431051]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2017:0499 https://rhn.redhat.com/errata/RHSA-2017-0499.html
Bugzilla
CVE-2017-5043 chromium-browser: use after free in guestview
bugzilla·2017-03-10·CVSS 8.8
CVE-2017-5043 [HIGH] CVE-2017-5043 chromium-browser: use after free in guestview
CVE-2017-5043 chromium-browser: use after free in guestview
An use after free flaw was found in the GuestView component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=683523
External References:
https://chromereleases.googleblog.com/2017/03/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: fedora-all [bug 1431051]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2017:0499 https://rhn.redhat.com/errata/RHSA-2017-0499.html
http://www.securityfocus.com/bid/96806http://www.securitytracker.com/id/1037968https://source.android.com/security/bulletin/2017-03-01https://source.android.com/security/bulletin/2017-03-01.htmlhttp://www.securityfocus.com/bid/96806http://www.securitytracker.com/id/1037968https://source.android.com/security/bulletin/2017-03-01
2017-03-08
Published