CVE-2017-0501
published 2017-03-08CVE-2017-0501: An elevation of privilege vulnerability in MediaTek components, including the M4U driver, sound driver, touchscreen driver, GPU driver, and Command Queue…
PriorityP337high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
EPSS
0.74%
50.6th percentile
An elevation of privilege vulnerability in MediaTek components, including the M4U driver, sound driver, touchscreen driver, GPU driver, and Command Queue driver, could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: N/A. Android ID: A-28430015. References: M-ALPS02708983.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | <= 7.1.1 | — | |
| android | — | — | |
| google_inc | android | — | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jpf8-mpcc-7g63: An elevation of privilege vulnerability in MediaTek components, including the M4U driver, sound driver, touchscreen driver, GPU driver, and Command Qu
ghsa_unreviewed·2022-05-13
CVE-2017-0501 [HIGH] GHSA-jpf8-mpcc-7g63: An elevation of privilege vulnerability in MediaTek components, including the M4U driver, sound driver, touchscreen driver, GPU driver, and Command Qu
An elevation of privilege vulnerability in MediaTek components, including the M4U driver, sound driver, touchscreen driver, GPU driver, and Command Queue driver, could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: N/A. Android ID: A-28430015. References: M-ALPS02708983.
OSV
CVE-2017-0501: An elevation of privilege vulnerability in MediaTek components, including the M4U driver, sound driver, touchscreen driver, GPU driver, and Command Qu
osv·2017-03-08·CVSS 7.8
CVE-2017-0501 [HIGH] CVE-2017-0501: An elevation of privilege vulnerability in MediaTek components, including the M4U driver, sound driver, touchscreen driver, GPU driver, and Command Qu
An elevation of privilege vulnerability in MediaTek components, including the M4U driver, sound driver, touchscreen driver, GPU driver, and Command Queue driver, could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: N/A. Android ID: A-28430015. References: M-ALPS02708983.
Android
CVE-2017-0501: Android Security Bulletin 2017-03-01
CVE: CVE-2017-0501
Severity: CRITICAL
References: A-28430015*
M-ALPS02708983
vendor_android·2017-03-01·CVSS 7.8
CVE-2017-0501 [HIGH] CVE-2017-0501: Android Security Bulletin 2017-03-01
CVE: CVE-2017-0501
Severity: CRITICAL
References: A-28430015*
M-ALPS02708983
Android Security Bulletin 2017-03-01
CVE: CVE-2017-0501
Severity: CRITICAL
References: A-28430015*
M-ALPS02708983
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-14475 mysql-mmm: arbitrary command execution with the privileges of the mmm_agentd process
bugzilla·2018-05-17·CVSS 9.8
CVE-2017-14475 [CRITICAL] CVE-2017-14475 mysql-mmm: arbitrary command execution with the privileges of the mmm_agentd process
CVE-2017-14475 mysql-mmm: arbitrary command execution with the privileges of the mmm_agentd process
A flaw was found in the MMM::Agent::Helpers::Network::add_ip function in MySQL Multi-Master Replication Manager (MMM) mmm_agentd 2.2.1 (for Linux), a specially crafted MMM protocol message can cause a shell command injection resulting in arbitrary command execution with the privileges of the mmm_agentd process. An attacker that can initiate a TCP session with mmm_agentd can trigger this vulnerability.
References:
https://www.talosintelligence.com/vulnerability_reports/TALOS-2017-0501
Discussion:
Created mysql-mmm tracking bugs for this issue:
Affects: epel-all [bug 1579449]
Affects: fedora-all [bug 1579450]
---
This CVE Bugzilla entry is for community support informational purposes o
Bugzilla
CVE-2017-14478 mysql-mmm: arbitrary command execution with the privileges of the mmm_agentd process
bugzilla·2018-05-17·CVSS 9.8
CVE-2017-14478 [CRITICAL] CVE-2017-14478 mysql-mmm: arbitrary command execution with the privileges of the mmm_agentd process
CVE-2017-14478 mysql-mmm: arbitrary command execution with the privileges of the mmm_agentd process
A flaw was found in the MMM::Agent::Helpers::Network::clear_ip function in MySQL Multi-Master Replication Manager (MMM) mmm_agentd 2.2.1 (for Linux), a specially crafted MMM protocol message can cause a shell command injection resulting in arbitrary command execution with the privileges of the mmm_agentd process. An attacker that can initiate a TCP session with mmm_agentd can trigger this vulnerability.
References:
https://www.talosintelligence.com/vulnerability_reports/TALOS-2017-0501
Discussion:
Created mysql-mmm tracking bugs for this issue:
Affects: epel-all [bug 1579449]
Affects: fedora-all [bug 1579450]
---
This CVE Bugzilla entry is for community support informational purposes
Bugzilla
CVE-2017-14477 mysql-mmm: arbitrary command execution with the privileges of the mmm_agentd process
bugzilla·2018-05-17·CVSS 9.8
CVE-2017-14477 [CRITICAL] CVE-2017-14477 mysql-mmm: arbitrary command execution with the privileges of the mmm_agentd process
CVE-2017-14477 mysql-mmm: arbitrary command execution with the privileges of the mmm_agentd process
A flaw was found in the MMM::Agent::Helpers::Network::add_ip function in MySQL Multi-Master Replication Manager (MMM) mmm_agentd 2.2.1 (for FreeBSD), a specially crafted MMM protocol message can cause a shell command injection resulting in arbitrary command execution with the privileges of the mmm_agentd process. An attacker that can initiate a TCP session with mmm_agentd can trigger this vulnerability.
References:
https://www.talosintelligence.com/vulnerability_reports/TALOS-2017-0501
Discussion:
Created mysql-mmm tracking bugs for this issue:
Affects: epel-all [bug 1579449]
Affects: fedora-all [bug 1579450]
---
This CVE Bugzilla entry is for community support informational purposes
Bugzilla
CVE-2017-14476 mysql-mmm: arbitrary command execution with the privileges of the mmm_agentd process
bugzilla·2018-05-17·CVSS 9.8
CVE-2017-14476 [CRITICAL] CVE-2017-14476 mysql-mmm: arbitrary command execution with the privileges of the mmm_agentd process
CVE-2017-14476 mysql-mmm: arbitrary command execution with the privileges of the mmm_agentd process
A flaw was found in In the MMM::Agent::Helpers::Network::add_ip function in MySQL Multi-Master Replication Manager (MMM) mmm_agentd 2.2.1 (for Solaris), a specially crafted MMM protocol message can cause a shell command injection resulting in arbitrary command execution with the privileges of the mmm_agentd process. An attacker that can initiate a TCP session with mmm_agentd can trigger this vulnerability.
References:
https://www.talosintelligence.com/vulnerability_reports/TALOS-2017-0501
Discussion:
Created mysql-mmm tracking bugs for this issue:
Affects: epel-all [bug 1579449]
Affects: fedora-all [bug 1579450]
---
This CVE Bugzilla entry is for community support informational purpo
Bugzilla
CVE-2017-14480 mysql-mmm: arbitrary command execution with the privileges of the mmm_agentd process
bugzilla·2018-05-17·CVSS 9.8
CVE-2017-14480 [CRITICAL] CVE-2017-14480 mysql-mmm: arbitrary command execution with the privileges of the mmm_agentd process
CVE-2017-14480 mysql-mmm: arbitrary command execution with the privileges of the mmm_agentd process
A flaw was found n the MMM::Agent::Helpers::Network::clear_ip function in MySQL Multi-Master Replication Manager (MMM) mmm_agentd 2.2.1 (for FreeBSD), a specially crafted MMM protocol message can cause a shell command injection resulting in arbitrary command execution with the privileges of the mmm_agentd process. An attacker that can initiate a TCP session with mmm_agentd can trigger this vulnerability.
References:
https://www.talosintelligence.com/vulnerability_reports/TALOS-2017-0501
Discussion:
Created mysql-mmm tracking bugs for this issue:
Affects: epel-all [bug 1579449]
Affects: fedora-all [bug 1579450]
---
This CVE Bugzilla entry is for community support informational purpose
Bugzilla
CVE-2017-14479 mysql-mmm: arbitrary command execution with the privileges of the mmm_agentd process
bugzilla·2018-05-17·CVSS 9.8
CVE-2017-14479 [CRITICAL] CVE-2017-14479 mysql-mmm: arbitrary command execution with the privileges of the mmm_agentd process
CVE-2017-14479 mysql-mmm: arbitrary command execution with the privileges of the mmm_agentd process
A flaw was found in the MMM::Agent::Helpers::Network::clear_ip function in MySQL Multi-Master Replication Manager (MMM) mmm_agentd 2.2.1 (for Solaris), a specially crafted MMM protocol message can cause a shell command injection resulting in arbitrary command execution with the privileges of the mmm_agentd process. An attacker that can initiate a TCP session with mmm_agentd can trigger this vulnerability.
References:
https://www.talosintelligence.com/vulnerability_reports/TALOS-2017-0501
Discussion:
Created mysql-mmm tracking bugs for this issue:
Affects: epel-all [bug 1579449]
Affects: fedora-all [bug 1579450]
---
This CVE Bugzilla entry is for community support informational purpos
Bugzilla
CVE-2017-14474 mysql-mmm: arbitrary command execution with the privileges of the mmm_agentd process
bugzilla·2018-05-10·CVSS 9.8
CVE-2017-14474 [CRITICAL] CVE-2017-14474 mysql-mmm: arbitrary command execution with the privileges of the mmm_agentd process
CVE-2017-14474 mysql-mmm: arbitrary command execution with the privileges of the mmm_agentd process
In the MMM::Agent::Helpers::_execute function in MySQL Multi-Master Replication Manager (MMM) mmm_agentd 2.2.1, a specially crafted MMM protocol message can cause a shell command injection resulting in arbitrary command execution with the privileges of the mmm_agentd process. An attacker that can initiate a TCP session with mmm_agentd can trigger this vulnerability.
References:
https://www.talosintelligence.com/vulnerability_reports/TALOS-2017-0501
https://bugzilla.redhat.com/show_bug.cgi?id=1575161
Discussion:
Created mysql-mmm tracking bugs for this issue:
Affects: epel-all [bug 1576895]
Affects: fedora-all [bug 1576894]
---
This CVE Bugzilla entry is for community support informat
Bugzilla
CVE-2017-14481 mysql-mmm: arbitrary command execution with the privileges of the mmm_agentd process
bugzilla·2018-05-10·CVSS 9.8
CVE-2017-14481 [CRITICAL] CVE-2017-14481 mysql-mmm: arbitrary command execution with the privileges of the mmm_agentd process
CVE-2017-14481 mysql-mmm: arbitrary command execution with the privileges of the mmm_agentd process
A flaw was found in the MMM::Agent::Helpers::Network::send_arp function in MySQL Multi-Master Replication Manager (MMM) mmm_agentd 2.2.1 (for Solaris), a specially crafted MMM protocol message can cause a shell command injection resulting in arbitrary command execution with the privileges of the mmm_agentd process. An attacker that can initiate a TCP session with mmm_agentd can trigger this vulnerability.
References:
https://www.talosintelligence.com/vulnerability_reports/TALOS-2017-0501
https://bugzilla.redhat.com/show_bug.cgi?id=1575161
Discussion:
Created mysql-mmm tracking bugs for this issue:
Affects: epel-all [bug 1576898]
Affects: fedora-all [bug 1576899]
---
This CVE Bugzilla
http://www.securityfocus.com/bid/96726http://www.securitytracker.com/id/1037968https://source.android.com/security/bulletin/2017-03-01https://source.android.com/security/bulletin/2017-03-01.htmlhttp://www.securityfocus.com/bid/96726http://www.securitytracker.com/id/1037968https://source.android.com/security/bulletin/2017-03-01
2017-03-08
Published