CVE-2017-0630
published 2017-05-12CVE-2017-0630: An information disclosure vulnerability in the kernel trace subsystem could enable a local malicious application to access data outside of its permission…
PriorityP419medium4.7CVSS 3.0
AVLACHPRNUIRSUCHINAN
EPSS
1.44%
70.3th percentile
An information disclosure vulnerability in the kernel trace subsystem could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-34277115.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | — | — |
| android | — | — | |
| google_inc | android | — | — |
| google_inc | android | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
CVSS provenance
nvdv3.04.7MEDIUMCVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.02.6LOWAV:N/AC:H/Au:N/C:P/I:N/A:N
osv4.7MEDIUM
vendor_debian4.7LOW
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-rmm8-qwj9-r9r3: An information disclosure vulnerability in the kernel trace subsystem could enable a local malicious application to access data outside of its permiss
ghsa_unreviewed·2022-05-17
CVE-2017-0630 [MEDIUM] CWE-200 GHSA-rmm8-qwj9-r9r3: An information disclosure vulnerability in the kernel trace subsystem could enable a local malicious application to access data outside of its permiss
An information disclosure vulnerability in the kernel trace subsystem could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-34277115.
OSV
CVE-2017-0630: An information disclosure vulnerability in the kernel trace subsystem could enable a local malicious application to access data outside of its permiss
osv·2017-05-12·CVSS 4.7
CVE-2017-0630 [MEDIUM] CVE-2017-0630: An information disclosure vulnerability in the kernel trace subsystem could enable a local malicious application to access data outside of its permiss
An information disclosure vulnerability in the kernel trace subsystem could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-34277115.
Red Hat
kernel: Information disclosure vulnerability in kernel trace subsystem
vendor_redhat·2017-05-01·CVSS 4.7
CVE-2017-0630 [MEDIUM] CWE-200 kernel: Information disclosure vulnerability in kernel trace subsystem
kernel: Information disclosure vulnerability in kernel trace subsystem
An information disclosure vulnerability in the kernel trace subsystem could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-34277115.
Package: kernel (Red Hat Enterprise Linux 5) - Will not fix
Package: kernel (Red Hat Enterprise Linux 6) - Will not fix
Package: kernel (Red Hat Enterprise Linux 7) - Will not fix
Package: kernel-rt (Red Hat Enterprise Linux 7) - Will not fix
Package: realtime-kernel (Red Hat Enterprise MRG 2) - Will not fix
Android
CVE-2017-0630: Android Security Bulletin 2017-05-01
CVE: CVE-2017-0630
Severity: MEDIUM
References: A-34277115*
vendor_android·2017-05-01·CVSS 4.7
CVE-2017-0630 [MEDIUM] CVE-2017-0630: Android Security Bulletin 2017-05-01
CVE: CVE-2017-0630
Severity: MEDIUM
References: A-34277115*
Android Security Bulletin 2017-05-01
CVE: CVE-2017-0630
Severity: MEDIUM
References: A-34277115*
Debian
CVE-2017-0630: linux - An information disclosure vulnerability in the kernel trace subsystem could enab...
vendor_debian·2017·CVSS 4.7
CVE-2017-0630 [MEDIUM] CVE-2017-0630: linux - An information disclosure vulnerability in the kernel trace subsystem could enab...
An information disclosure vulnerability in the kernel trace subsystem could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-34277115.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-0630 kernel: Information disclosure vulnerability in kernel trace subsystem
bugzilla·2017-05-11·CVSS 4.7
CVE-2017-0630 [MEDIUM] CVE-2017-0630 kernel: Information disclosure vulnerability in kernel trace subsystem
CVE-2017-0630 kernel: Information disclosure vulnerability in kernel trace subsystem
An information disclosure vulnerability in the kernel trace subsystem could enable a local malicious application to access data outside of its permission levels. Compromising a privileged process is first required.
External References:
https://source.android.com/security/bulletin/2017-05-01#id-in-kernel-trace-subsystem
Bugzilla
CVE-2016-10207 tigervnc: VNC server can crash when TLS handshake terminates early
bugzilla·2017-02-02·CVSS 7.5
CVE-2016-10207 [HIGH] CVE-2016-10207 tigervnc: VNC server can crash when TLS handshake terminates early
CVE-2016-10207 tigervnc: VNC server can crash when TLS handshake terminates early
A vulnerability was found in tigerVNC. The Xvnc server from tigervnc can crash when a client terminates a TLS connection early. This is due to invalid initialization/deinitialization order of the GnuTLS library.
References:
http://seclists.org/oss-sec/2017/q1/297
Upstream patch:
https://github.com/TigerVNC/tigervnc/commit/8aa4bc53206c2430bbf0c8f4b642f59a379ee649
Discussion:
Created tigervnc tracking bugs for this issue:
Affects: fedora-all [bug 1415719]
---
CVE assignment:
http://seclists.org/oss-sec/2017/q1/312
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2017:0630 https://rhn.redhat.com/errata/RHSA-2017-0630.html
---
This issue has been ad
2017-05-12
Published