CVE-2017-0725
published 2017-08-09CVE-2017-0725: A denial of service vulnerability in the Android media framework (libskia). Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-37627194.
PriorityP415medium5.5CVSS 3.0
AVLACLPRNUIRSUCNINAH
EPSS
0.37%
29.0th percentile
A denial of service vulnerability in the Android media framework (libskia). Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-37627194.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| google_inc | android | — | — |
| google_inc | android | — | — |
| google_inc | android | — | — |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Android
CVE-2017-0725: Android Security Bulletin 2017-08-01
CVE: CVE-2017-0725
Severity: HIGH
Type: DoS
Affected AOSP versions: 7
vendor_android·2017-08-01·CVSS 5.5
CVE-2017-0725 [MEDIUM] CVE-2017-0725: Android Security Bulletin 2017-08-01
CVE: CVE-2017-0725
Severity: HIGH
Type: DoS
Affected AOSP versions: 7
Android Security Bulletin 2017-08-01
CVE: CVE-2017-0725
Severity: HIGH
Type: DoS
Affected AOSP versions: 7.0, 7.1.1, 7.1.2
References: A-37627194
GHSA
GHSA-vc7v-3fm2-888p: A denial of service vulnerability in the Android media framework (libskia)
ghsa_unreviewed·2022-05-13
CVE-2017-0725 [MEDIUM] CWE-125 GHSA-vc7v-3fm2-888p: A denial of service vulnerability in the Android media framework (libskia)
A denial of service vulnerability in the Android media framework (libskia). Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-37627194.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-9401 bash: popd controlled free
bugzilla·2016-11-18·CVSS 5.5
CVE-2016-9401 [MEDIUM] CVE-2016-9401 bash: popd controlled free
CVE-2016-9401 bash: popd controlled free
A vulnerability was found in popd. It can be tricked to free a user supplied address in the following way:
$ popd +-111111
This could be used to bypass restricted shells (rsh) on some environments to cause use-after-free.
References:
http://seclists.org/oss-sec/2016/q4/445
Discussion:
Created bash tracking bugs for this issue:
Affects: fedora-all [bug 1396387]
---
Upstream report:
https://lists.gnu.org/archive/html/bug-bash/2016-11/msg00099.html
Upstream patch:
https://lists.gnu.org/archive/html/bug-bash/2016-11/msg00116.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2017:0725 https://rhn.redhat.com/errata/RHSA-2017-0725.html
---
This issue has been addressed in the following
Bugzilla
CVE-2016-7543 bash: Specially crafted SHELLOPTS+PS4 variables allows command substitution
bugzilla·2016-09-27·CVSS 8.4
CVE-2016-7543 [HIGH] CVE-2016-7543 bash: Specially crafted SHELLOPTS+PS4 variables allows command substitution
CVE-2016-7543 bash: Specially crafted SHELLOPTS+PS4 variables allows command substitution
Shells running as root inherited PS4 from the environment, allowing PS4 expansion performing command substitution. Local attacker could gain arbitrary code execution via bogus setuid binaries using system()/popen() by specially crafting SHELLOPTS+PS4 environment variables.
Public announcement:
http://seclists.org/oss-sec/2016/q3/617
Discussion:
Created bash tracking bugs for this issue:
Affects: fedora-all [bug 1379634]
---
Upstream patch (for bash-4.3):
http://lists.gnu.org/archive/html/bug-bash/2016-10/msg00009.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2017:0725 https://rhn.redhat.com/errata/RHSA-2017-0725.html
---
This issue
2017-08-09
Published