CVE-2017-0705
published 2017-07-06CVE-2017-0705: A elevation of privilege vulnerability in the Broadcom wi-fi driver. Product: Android. Versions: Android kernel. Android ID: A-34973477. References…
PriorityP425medium6.8CVSS 3.0
AVPACLPRNUINSUCHIHAH
EPSS
0.18%
8.3th percentile
A elevation of privilege vulnerability in the Broadcom wi-fi driver. Product: Android. Versions: Android kernel. Android ID: A-34973477. References: B-RB#119898.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| google_inc | android | — | — |
CVSS provenance
nvdv3.06.8MEDIUMCVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Android
CVE-2017-0705: Wi-Fi driver
vendor_android·2017-07-01·CVSS 6.8
CVE-2017-0705 [MEDIUM] CVE-2017-0705: Wi-Fi driver
Android Security Bulletin 2017-07-01
CVE: CVE-2017-0705
Severity: MEDIUM
Type: EoP
Component: Wi-Fi driver
References: A-34973477*
B-RB#119898
GHSA
GHSA-crcf-h54q-v2hp: A elevation of privilege vulnerability in the Broadcom wi-fi driver
ghsa_unreviewed·2022-05-13
CVE-2017-0705 [HIGH] GHSA-crcf-h54q-v2hp: A elevation of privilege vulnerability in the Broadcom wi-fi driver
A elevation of privilege vulnerability in the Broadcom wi-fi driver. Product: Android. Versions: Android kernel. Android ID: A-34973477. References: B-RB#119898.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-12900 tcpdump: Buffer over-read in util-print.c:tok2strbuf()
bugzilla·2017-09-11·CVSS 9.8
CVE-2017-12900 [CRITICAL] CVE-2017-12900 tcpdump: Buffer over-read in util-print.c:tok2strbuf()
CVE-2017-12900 tcpdump: Buffer over-read in util-print.c:tok2strbuf()
Buffer over-read in util-print.c:tok2strbuf() was found.
This vulnerability can be exploited in two ways. The first is to produce a .pcap file with crafted packet(s) for the protocol(s) concerned and make the target system try to decode the file using tcpdump. The second is to send specially crafted packet(s) to the network segment where the target system is running a tcpdump process that is decoding a live packet capture. In the latter case it depends on the specific network protocol if the crafted packet(s) may be sent from the local segment only or from a remote Internet host.
Discussion:
Acknowledgments:
Name: the Tcpdump project
---
This issue was addressed in Red Hat Enterprise Linux 7 via RHEA-2018:0705, wh
Bugzilla
CVE-2017-11542 tcpdump: heap-based buffer over-read in the pimv1_print
bugzilla·2017-07-26·CVSS 9.8
CVE-2017-11542 [CRITICAL] CVE-2017-11542 tcpdump: heap-based buffer over-read in the pimv1_print
CVE-2017-11542 tcpdump: heap-based buffer over-read in the pimv1_print
tcpdump 4.9.0 has a heap-based buffer over-read in the pimv1_print function in print-pim.c.
Reproducer:
https://github.com/hackerlib/hackerlib-vul/tree/master/tcpdump-vul/heap-buffer-overflow/print-pim
Discussion:
Created tcpdump tracking bugs for this issue:
Affects: fedora-all [bug 1475364]
---
This issue was addressed in Red Hat Enterprise Linux 7 via RHEA-2018:0705, which rebased tcpdump to 4.9.2:
https://access.redhat.com/errata/RHEA-2018:0705
Bugzilla
CVE-2017-11544 tcpdump: Segmentation Violation in the compressed_sl_print
bugzilla·2017-07-26·CVSS 9.8
CVE-2017-11544 [CRITICAL] CVE-2017-11544 tcpdump: Segmentation Violation in the compressed_sl_print
CVE-2017-11544 tcpdump: Segmentation Violation in the compressed_sl_print
tcpdump 4.9.0 has a Segmentation Violation in the compressed_sl_print function in print-sl.c:229:3.
Reproducer:
https://github.com/hackerlib/hackerlib-vul/tree/master/tcpdump-vul/segv/print-sl
Discussion:
Created tcpdump tracking bugs for this issue:
Affects: fedora-all [bug 1475364]
---
Statement:
Red Hat Product Security has rated this issue as having Low security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
---
This issue was addressed in Red Hat Enterprise Linux 7 via RHEA-2018:0705, which rebased tcpdump to 4.9.2:
https://access.redhat.c
Bugzilla
CVE-2017-11541 tcpdump: heap-based buffer over-read in the lldp_print
bugzilla·2017-07-26·CVSS 9.8
CVE-2017-11541 [CRITICAL] CVE-2017-11541 tcpdump: heap-based buffer over-read in the lldp_print
CVE-2017-11541 tcpdump: heap-based buffer over-read in the lldp_print
tcpdump 4.9.0 has a heap-based buffer over-read in the lldp_print function in print-lldp.c, related to util-print.c.
Reproducer:
https://github.com/hackerlib/hackerlib-vul/tree/master/tcpdump-vul/heap-buffer-overflow/util-print
Discussion:
Created tcpdump tracking bugs for this issue:
Affects: fedora-all [bug 1475364]
---
This issue was addressed in Red Hat Enterprise Linux 7 via RHEA-2018:0705, which rebased tcpdump to 4.9.2:
https://access.redhat.com/errata/RHEA-2018:0705
http://www.securityfocus.com/bid/99482https://github.com/ScottyBauer/Android_Kernel_CVE_POCs/blob/master/CVE-2017-0705.chttps://source.android.com/security/bulletin/2017-07-01http://www.securityfocus.com/bid/99482https://github.com/ScottyBauer/Android_Kernel_CVE_POCs/blob/master/CVE-2017-0705.chttps://source.android.com/security/bulletin/2017-07-01
2017-07-06
Published