CVE-2017-0666
published 2017-07-06CVE-2017-0666: A elevation of privilege vulnerability in the Android framework. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID…
PriorityP434high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
EPSS
0.44%
35.4th percentile
A elevation of privilege vulnerability in the Android framework. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37285689.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| google_inc | android | — | — |
| steveklabnik | request_store | >= 1.3.2 < 1.4.0 | 1.4.0 |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
request_store has Incorrect Default Permissions
ghsa·2024-08-23
CVE-2024-43791 [MEDIUM] CWE-276 request_store has Incorrect Default Permissions
request_store has Incorrect Default Permissions
### Impact
The files published as part of request_store 1.3.2 have 0666 permissions, meaning that they are world-writable, which allows local users to execute arbitrary code.
This version was published in 2017, and most production environments do not allow access for local users, so the chances of this being exploited are very low, given that the vast majority of users will have upgraded, and those that have not, if any, are not likely to be exposed.
### Patches
I am not aware of any other version of the gem with incorrect permissions, so simply upgrading should fix the issue.
### Workarounds
You could chmod the files yourself, I guess.
### References
https://cwe.mitre.org/data/definitions/276.html
GHSA
GHSA-4xjf-ffmr-pj4g: A elevation of privilege vulnerability in the Android framework
ghsa_unreviewed·2022-05-13
CVE-2017-0666 [HIGH] CWE-682 GHSA-4xjf-ffmr-pj4g: A elevation of privilege vulnerability in the Android framework
A elevation of privilege vulnerability in the Android framework. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37285689.
OSV
CVE-2017-0666: A elevation of privilege vulnerability in the Android framework
osv·2017-07-06·CVSS 7.8
CVE-2017-0666 [HIGH] CVE-2017-0666: A elevation of privilege vulnerability in the Android framework
A elevation of privilege vulnerability in the Android framework. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37285689.
Red Hat
RequestStore: Incorrect Default Permissions in request_store 1.3.2
vendor_redhat·2024-08-23·CVSS 7.8
CVE-2024-43791 [HIGH] CWE-276 RequestStore: Incorrect Default Permissions in request_store 1.3.2
RequestStore: Incorrect Default Permissions in request_store 1.3.2
RequestStore provides per-request global storage for Rack. The files published as part of request_store 1.3.2 have 0666 permissions, meaning that they are world-writable, which allows local users to execute arbitrary code. This version was published in 2017, and most production environments do not allow access for local users, so the chances of this being exploited are very low, given that the vast majority of users will have upgraded, and those that have not, if any, are not likely to be exposed.
A flaw was found in RequestStore, which provides per-request global storage. This flaw allows a malicious user to execute arbitrary code due to global permission issues.
Package: 3scale-amp-system-container (Red Hat 3scale API
Android
CVE-2017-0666: Android Security Bulletin 2017-07-01
CVE: CVE-2017-0666
Severity: HIGH
Type: EoP
Affected AOSP versions: 4
vendor_android·2017-07-01·CVSS 7.8
CVE-2017-0666 [HIGH] CVE-2017-0666: Android Security Bulletin 2017-07-01
CVE: CVE-2017-0666
Severity: HIGH
Type: EoP
Affected AOSP versions: 4
Android Security Bulletin 2017-07-01
CVE: CVE-2017-0666
Severity: HIGH
Type: EoP
Affected AOSP versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2
References: A-37285689
No detection rules found.
No public exploits indexed.
2017-07-06
Published