CVE-2017-0557
published 2017-04-07CVE-2017-0557: An information disclosure vulnerability in libmpeg2 in Mediaserver could enable a local malicious application to access data outside of its permission levels…
PriorityP420medium5.5CVSS 3.0
AVLACLPRNUIRSUCHINAN
EPSS
0.60%
44.6th percentile
An information disclosure vulnerability in libmpeg2 in Mediaserver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access data without permission. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-34093073.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| google_inc | android | — | — |
| google_inc | android | — | — |
| google_inc | android | — | — |
| google_inc | android | — | — |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Android
CVE-2017-0557: Android Security Bulletin 2017-04-01
CVE: CVE-2017-0557
Severity: MEDIUM
Affected AOSP versions: 6
vendor_android·2017-04-01·CVSS 5.5
CVE-2017-0557 [MEDIUM] CVE-2017-0557: Android Security Bulletin 2017-04-01
CVE: CVE-2017-0557
Severity: MEDIUM
Affected AOSP versions: 6
Android Security Bulletin 2017-04-01
CVE: CVE-2017-0557
Severity: MEDIUM
Affected AOSP versions: 6.0, 6.0.1, 7.0, 7.1.1
References: A-34093073
GHSA
GHSA-hvx8-2xcq-p4m2: An information disclosure vulnerability in libmpeg2 in Mediaserver could enable a local malicious application to access data outside of its permission
ghsa_unreviewed·2022-05-17
CVE-2017-0557 [MEDIUM] CWE-200 GHSA-hvx8-2xcq-p4m2: An information disclosure vulnerability in libmpeg2 in Mediaserver could enable a local malicious application to access data outside of its permission
An information disclosure vulnerability in libmpeg2 in Mediaserver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access data without permission. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-34093073.
OSV
CVE-2017-0557: An information disclosure vulnerability in libmpeg2 in Mediaserver could enable a local malicious application to access data outside of its permission
osv·2017-04-07·CVSS 5.5
CVE-2017-0557 [MEDIUM] CVE-2017-0557: An information disclosure vulnerability in libmpeg2 in Mediaserver could enable a local malicious application to access data outside of its permission
An information disclosure vulnerability in libmpeg2 in Mediaserver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access data without permission. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-34093073.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-2658 Dashbuilder: Lack of clickjacking protection on the login page
bugzilla·2017-03-16·CVSS 2.6
CVE-2017-2658 [LOW] CVE-2017-2658 Dashbuilder: Lack of clickjacking protection on the login page
CVE-2017-2658 Dashbuilder: Lack of clickjacking protection on the login page
It was discovered that the Dashbuilder login page could be opened in an IFRAME, which made it possible to intercept and manipulate requests. An attacker could use this flaw to trick a user into performing arbitrary actions in the Console (clickjacking).
Discussion:
Acknowledgments:
Name: Martin Weiler (Red Hat)
---
This issue has been addressed in the following products:
Red Hat JBoss BPM Suite 6.4.2
Via RHSA-2017:0557 https://rhn.redhat.com/errata/RHSA-2017-0557.html
---
This issue has been addressed in the following products:
Red Hat JBoss Data Virtualization
Via RHSA-2018:2243 https://access.redhat.com/errata/RHSA-2018:2243
Bugzilla
CVE-2016-6343 Dashbuilder: Reflected XSS
bugzilla·2016-08-31·CVSS 6.1
CVE-2016-6343 [MEDIUM] CVE-2016-6343 Dashbuilder: Reflected XSS
CVE-2016-6343 Dashbuilder: Reflected XSS
JBoss BPM Suite 6 is vulnerable to a reflected XSS via dashbuilder. Remote attackers can entice authenticated users that have privileges to access dashbuilder (usually admins) to click on links to /dashbuilder/Controller containing malicious scripts. Successful exploitation would allow execution of script code within the context of the affected user.
Discussion:
Acknowledgments:
Name: Jeremy Choi (Red Hat Product Security Team)
---
Hi @Jeremy,
I'm not sure if I get what's the issue here. Can you please elaborate a bit more, and also give a detailed reproducer.
Thanks in advance.
---
This issue has been addressed in the following products:
Red Hat JBoss BPM Suite 6.4.2
Via RHSA-2017:0557 https://rhn.redhat.com/errata/RHSA-2017-0557.html
http://www.securityfocus.com/bid/97332http://www.securitytracker.com/id/1038201https://android.googlesource.com/platform/external/libmpeg2/+/227c1f829127405e21dab1664393050c652ef71ehttps://source.android.com/security/bulletin/2017-04-01http://www.securityfocus.com/bid/97332http://www.securitytracker.com/id/1038201https://android.googlesource.com/platform/external/libmpeg2/+/227c1f829127405e21dab1664393050c652ef71ehttps://source.android.com/security/bulletin/2017-04-01
2017-04-07
Published