CVE-2017-0640
published 2017-06-14CVE-2017-0640: A remote denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue…
PriorityP418medium5.5CVSS 3.0
AVLACLPRNUIRSUCNINAH
EPSS
0.66%
47.5th percentile
A remote denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-33129467.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| google_inc | android | — | — |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.07.1HIGHAV:N/AC:M/Au:N/C:N/I:N/A:C
osv5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qmcf-vc5w-fwpw: A remote denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot
ghsa_unreviewed·2022-05-13
CVE-2017-0640 [HIGH] GHSA-qmcf-vc5w-fwpw: A remote denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot
A remote denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-33129467.
OSV
CVE-2017-0640: A remote denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot
osv·2017-06-14·CVSS 5.5
CVE-2017-0640 [MEDIUM] CVE-2017-0640: A remote denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot
A remote denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-33129467.
Red Hat
vim: Sets the group ownership of a .swp file to the editor's primary group
vendor_redhat·2017-11-04·CVSS 5.5
CVE-2017-17087 [MEDIUM] CWE-266 vim: Sets the group ownership of a .swp file to the editor's primary group
vim: Sets the group ownership of a .swp file to the editor's primary group
fileio.c in Vim prior to 8.0.1263 sets the group ownership of a .swp file to the editor's primary group (which may be different from the group ownership of the original file), which allows local users to obtain sensitive information by leveraging an applicable group membership, as demonstrated by /etc/shadow owned by root:shadow mode 0640, but /etc/.shadow.swp owned by root:users mode 0640, a different vulnerability than CVE-2017-1000382.
It was found that the swap file created by vim when opening a file was using the user's primary group instead of the file's group. An attacker belonging to the victim's primary group could use this flaw to read the vim swap file.
Statement: Red Hat Product Security has rated thi
Android
CVE-2017-0640: Android Security Bulletin 2017-06-01
CVE: CVE-2017-0640
Severity: HIGH
Type: DoS
Affected AOSP versions: 6
vendor_android·2017-06-01·CVSS 5.5
CVE-2017-0640 [MEDIUM] CVE-2017-0640: Android Security Bulletin 2017-06-01
CVE: CVE-2017-0640
Severity: HIGH
Type: DoS
Affected AOSP versions: 6
Android Security Bulletin 2017-06-01
CVE: CVE-2017-0640
Severity: HIGH
Type: DoS
Affected AOSP versions: 6.0, 6.0.1, 7.0, 7.1.1
References: A-33129467*
No detection rules found.
No public exploits indexed.
2017-06-14
Published