CVE-2017-0510
published 2017-03-08CVE-2017-0510: An elevation of privilege vulnerability in the kernel FIQ debugger could enable a local malicious application to execute arbitrary code within the context of…
PriorityP340high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
EPSS
1.84%
76.6th percentile
An elevation of privilege vulnerability in the kernel FIQ debugger could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: Kernel-3.10. Android ID: A-32402555.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | — | — |
| android | — | — | |
| google_inc | android | — | — |
| linux | linux_kernel | — | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian7.8LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Android
CVE-2017-0510: Android Security Bulletin 2017-03-01
CVE: CVE-2017-0510
Severity: CRITICAL
References: A-32402555*
vendor_android·2017-03-01·CVSS 7.8
CVE-2017-0510 [HIGH] CVE-2017-0510: Android Security Bulletin 2017-03-01
CVE: CVE-2017-0510
Severity: CRITICAL
References: A-32402555*
Android Security Bulletin 2017-03-01
CVE: CVE-2017-0510
Severity: CRITICAL
References: A-32402555*
Debian
CVE-2017-0510: linux - An elevation of privilege vulnerability in the kernel FIQ debugger could enable ...
vendor_debian·2017·CVSS 7.8
CVE-2017-0510 [HIGH] CVE-2017-0510: linux - An elevation of privilege vulnerability in the kernel FIQ debugger could enable ...
An elevation of privilege vulnerability in the kernel FIQ debugger could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: Kernel-3.10. Android ID: A-32402555.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-m9w9-wcvq-jx6v: An elevation of privilege vulnerability in the kernel FIQ debugger could enable a local malicious application to execute arbitrary code within the con
ghsa_unreviewed·2022-05-13
CVE-2017-0510 [HIGH] GHSA-m9w9-wcvq-jx6v: An elevation of privilege vulnerability in the kernel FIQ debugger could enable a local malicious application to execute arbitrary code within the con
An elevation of privilege vulnerability in the kernel FIQ debugger could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: Kernel-3.10. Android ID: A-32402555.
OSV
CVE-2017-0510: An elevation of privilege vulnerability in the kernel FIQ debugger could enable a local malicious application to execute arbitrary code within the con
osv·2017-03-08·CVSS 7.8
CVE-2017-0510 [HIGH] CVE-2017-0510: An elevation of privilege vulnerability in the kernel FIQ debugger could enable a local malicious application to execute arbitrary code within the con
An elevation of privilege vulnerability in the kernel FIQ debugger could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: Kernel-3.10. Android ID: A-32402555.
No detection rules found.
No public exploits indexed.
Talos
Vulnerability Spotlight: Dovecot out-of-bounds Read Vulnerability
blogs_talos·2018-03-01·CVSS 5.9
[MEDIUM] Vulnerability Spotlight: Dovecot out-of-bounds Read Vulnerability
## Vulnerability Spotlight: Dovecot out-of-bounds Read Vulnerability
## Overview
Today, Cisco Talos is disclosing a single out-of-bounds read vulnerability in the Dovecot IMAP server. Dovecot is a popular internet message access protocol, or IMAP, server with performance and security-oriented design. It is a popular choice for robust email servers. In accordance with our coordinated disclosure policy, Talos has worked with Dovecot to ensure that this issue has been resolved. Dovecot has released version 2.2.34 to address this issue. Talos recommends installing this update as quickly as possible on affected systems.
## Details
Discovered by Aleksander Nikolic
TALOS-2017-0510 / CVE-2017-14461 is an out-of-bounds read vulnerability in the RFC822 parser implemented in Dovecot IMAP Server
Talos
Vulnerability Spotlight: Dovecot out-of-bounds Read Vulnerability
blogs_talos·2018-03-01·CVSS 5.9
[MEDIUM] Vulnerability Spotlight: Dovecot out-of-bounds Read Vulnerability
## Overview
Today, Cisco Talos is disclosing a single out-of-bounds read vulnerability in the Dovecot IMAP server. Dovecot is a popular internet message access protocol, or IMAP, server with performance and security-oriented design. It is a popular choice for robust email servers. In accordance with our coordinated disclosure policy, Talos has worked with Dovecot to ensure that this issue has been resolved. Dovecot has released version 2.2.34 to address this issue. Talos recommends installing this update as quickly as possible on affected systems.
## Details
Discovered by Aleksander Nikolic
TALOS-2017-0510 / CVE-2017-14461 is an out-of-bounds read vulnerability in the RFC822 parser implemented in Dovecot IMAP Server 2.2.33.2. RFC822 deals specifically with the standard for ARPA interne
http://www.securityfocus.com/bid/96800http://www.securitytracker.com/id/1037968https://alephsecurity.com/2017/03/08/nexus9-fiq-debugger/https://source.android.com/security/bulletin/2017-03-01https://source.android.com/security/bulletin/2017-03-01.htmlhttp://www.securityfocus.com/bid/96800http://www.securitytracker.com/id/1037968https://alephsecurity.com/2017/03/08/nexus9-fiq-debugger/https://source.android.com/security/bulletin/2017-03-01
2017-03-08
Published