CVE-2017-7000
published 2018-04-03CVE-2017-7000: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. The issue involves the "SQLite" component…
PriorityP345high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
2.93%
85.6th percentile
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. The issue involves the "SQLite" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios | — | — |
| apple | iphone_os | < 10.3.2 | 10.3.2 |
| apple | mac_os_x | < 10.12.5 | 10.12.5 |
| apple | macos_sierra_10.12.5_security_update_2017-002_el_capitan_and_security_update_201 | — | — |
| chromium | chromium | < 61.0.3163.79 | 61.0.3163.79 |
| debian | debian_linux | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_redhat8.8HIGH
vendor_cisco5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Multilayer Director, Nexus 7000 Series, and Nexus 7700 Series Switches Bash Shell Unauthorized Access Vulnerability
vendor_cisco·2017-11-29·CVSS 4.2
CVE-2017-12340 [MEDIUM] CWE-284 Cisco Multilayer Director, Nexus 7000 Series, and Nexus 7700 Series Switches Bash Shell Unauthorized Access Vulnerability
Cisco Multilayer Director, Nexus 7000 Series, and Nexus 7700 Series Switches Bash Shell Unauthorized Access Vulnerability
A vulnerability in Cisco NX-OS System Software running on Cisco MDS Multilayer Director Switches, Cisco Nexus 7000 Series Switches, and Cisco Nexus 7700 Series Switches could allow an authenticated, local attacker to access the Bash shell of an affected device's operating system, even if the Bash shell is disabled on the system.
The vulnerability is due to insufficient sanitization of user-supplied parameters that are passed to certain functions of the Python scripting sandbox of the affected system. An attacker could exploit this vulnerability to escape the scripting sandbox and enter the Bash shell of the operating system with the privileges of the authenticated use
Red Hat
chromium-browser: pointer disclosure in sqlite
vendor_redhat·2017-07-25·CVSS 8.8
CVE-2017-7000 [HIGH] chromium-browser: pointer disclosure in sqlite
chromium-browser: pointer disclosure in sqlite
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. The issue involves the "SQLite" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.
Package: sqlite (Red Hat Enterprise Linux 5) - Will not fix
Package: sqlite (Red Hat Enterprise Linux 6) - Will not fix
Package: sqlite (Red Hat Enterprise Linux 7) - Will not fix
Package: mingw-virt-viewer (Red Hat Enterprise Virtualization 3) - Will not fix
Apple
CVE-2017-7000: macOS Sierra 10.12.5, Security Update 2017-002 El Capitan, and Security Update 2017-002 Yosemite
vendor_apple·2017-05-15·CVSS 8.8
CVE-2017-7000 [HIGH] CVE-2017-7000: macOS Sierra 10.12.5, Security Update 2017-002 El Capitan, and Security Update 2017-002 Yosemite
Apple Security Update: About the security content of macOS Sierra 10.12.5, Security Update 2017-002 El Capitan, and Security Update 2017-002 Yosemite
Product: macOS Sierra 10.12.5, Security Update 2017-002 El Capitan, and Security Update 2017-002 Yosemite
CVE: CVE-2017-7000
Component: SQLite
Impact: Processing maliciously crafted web content may lead to arbitrary code execution
Description: Multiple memory corruption issues were addressed with improved input validation.
Apple
CVE-2017-7000: iOS 10.3.2
vendor_apple·2017-05-15·CVSS 8.8
CVE-2017-7000 [HIGH] CVE-2017-7000: iOS 10.3.2
Apple Security Update: About the security content of iOS 10.3.2
Product: iOS
Version: 10.3.2
CVE: CVE-2017-7000
Component: SQLite
Impact: Processing maliciously crafted web content may lead to arbitrary code execution
Description: Multiple memory corruption issues were addressed with improved input validation.
Cisco
Cisco Nexus 7000 Series Switches Access-Control Filtering Mechanisms Bypass Vulnerability
vendor_cisco·2017-03-15·CVSS 5.8
CVE-2017-3875 [MEDIUM] CWE-20 Cisco Nexus 7000 Series Switches Access-Control Filtering Mechanisms Bypass Vulnerability
Cisco Nexus 7000 Series Switches Access-Control Filtering Mechanisms Bypass Vulnerability
A vulnerability in certain access-control filtering mechanisms on Cisco Nexus 7000 Series Switches could allow an unauthenticated, remote attacker to bypass defined traffic configured within an access control list (ACL) on the affected system.
The vulnerability is due to the device failing to inspect specific traffic when other ACL checking mechanisms are in place. An attacker could exploit this vulnerability by issuing crafted commands for which a particular ACL would not match defined traffic. An exploit could allow the attacker to bypass certain rulesets defined on a Network Time Protocol (NTP) ACL.
There are no workarounds that address this vulnerability.
This advisory is available at the foll
Cisco
Cisco Nexus 5000, 6000, and 7000 Series Switches Software IS-IS Packet Processing Denial of Service Vulnerability
vendor_cisco·2017-01-18·CVSS 5.8
CVE-2017-3804 [MEDIUM] CWE-399 Cisco Nexus 5000, 6000, and 7000 Series Switches Software IS-IS Packet Processing Denial of Service Vulnerability
Cisco Nexus 5000, 6000, and 7000 Series Switches Software IS-IS Packet Processing Denial of Service Vulnerability
A vulnerability in Intermediate System-to-Intermediate System (IS-IS) protocol packet processing of Cisco Nexus 5000, 6000, and 7000 Series Switches software could allow an unauthenticated, adjacent attacker to cause a reload of the affected device.
The vulnerability is due to improper processing of crafted IS-IS protocol packets. An attacker could exploit this vulnerability by sending a crafted IS-IS protocol packet over an established adjacency. An exploit could allow the attacker to cause a reload of the affected device.
There are no workarounds that address this vulnerability.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/cen
Cisco
Cisco Nexus 7000 Series Switches Access-Control Filtering Mechanisms Bypass Vulnerability
vendor_cisco·CVSS 3.0
CVE-2017-3875 Cisco Nexus 7000 Series Switches Access-Control Filtering Mechanisms Bypass Vulnerability
CVE-2017-3875: Cisco Nexus 7000 Series Switches Access-Control Filtering Mechanisms Bypass Vulnerability
A vulnerability in certain access-control filtering mechanisms on Cisco Nexus 7000 Series Switches could allow an unauthenticated, remote attacker to bypass defined traffic configured within an access control list (ACL) on the affected system. The vulnerability is due to the device failing to inspect specific traffic when other ACL checking mechanisms are in place. An attacker could exploit this vulnerability by issuing crafted commands for which a particular ACL would not match defined traffic. An exploit could allow the attacker to bypass certain rulesets defined on a Network Time Protocol (NTP) ACL. There are no
CVSS: 3.0
CWE: CWE-20, CWE-20
Bug IDs: CSCtz59354
Cisco
Cisco Nexus 5000, 6000, and 7000 Series Switches Software IS-IS Packet Processing Denial of Service Vulnerability
vendor_cisco·CVSS 3.0
CVE-2017-3804 Cisco Nexus 5000, 6000, and 7000 Series Switches Software IS-IS Packet Processing Denial of Service Vulnerability
CVE-2017-3804: Cisco Nexus 5000, 6000, and 7000 Series Switches Software IS-IS Packet Processing Denial of Service Vulnerability
A vulnerability in Intermediate System-to-Intermediate System (IS-IS) protocol packet processing of Cisco Nexus 5000, 6000, and 7000 Series Switches software could allow an unauthenticated, adjacent attacker to cause a reload of the affected device. The vulnerability is due to improper processing of crafted IS-IS protocol packets. An attacker could exploit this vulnerability by sending a crafted IS-IS protocol packet over an established adjacency. An exploit could allow the attacker to cause a reload of the affected device. There are no
CVSS: 3.0
CWE: CWE-399, CWE-399
Bug IDs: CSCvc45002
Cisco
Cisco Multilayer Director, Nexus 7000 Series, and Nexus 7700 Series Switches Bash Shell Unauthorized Access Vulnerability
vendor_cisco·CVSS 3.0
CVE-2017-12340 Cisco Multilayer Director, Nexus 7000 Series, and Nexus 7700 Series Switches Bash Shell Unauthorized Access Vulnerability
CVE-2017-12340: Cisco Multilayer Director, Nexus 7000 Series, and Nexus 7700 Series Switches Bash Shell Unauthorized Access Vulnerability
A vulnerability in Cisco NX-OS System Software running on Cisco MDS Multilayer Director Switches, Cisco Nexus 7000 Series Switches, and Cisco Nexus 7700 Series Switches could allow an authenticated, local attacker to access the Bash shell of an affected device's operating system, even if the Bash shell is disabled on the system. The vulnerability is due to insufficient sanitization of user-supplied parameters that are passed to certain functions of the Python scripting sandbox of the affected system. An attacker could exploit this vulnerability to escape the scripting sandbox and enter the Bash shell of the operating system with the privileges of the aut
GHSA
GHSA-2x84-5f93-3cpg: An issue was discovered in certain Apple products
ghsa_unreviewed·2022-05-14
CVE-2017-7000 [HIGH] CWE-119 GHSA-2x84-5f93-3cpg: An issue was discovered in certain Apple products
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. The issue involves the "SQLite" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.
OSV
CVE-2017-7000: An issue was discovered in certain Apple products
osv·2018-04-03·CVSS 8.8
CVE-2017-7000 [HIGH] CVE-2017-7000: An issue was discovered in certain Apple products
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. The issue involves the "SQLite" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-7000 sqlite: chromium-browser: pointer disclosure in sqlite [fedora-all]
bugzilla·2017-08-07·CVSS 8.8
CVE-2017-7000 [HIGH] CVE-2017-7000 sqlite: chromium-browser: pointer disclosure in sqlite [fedora-all]
CVE-2017-7000 sqlite: chromium-browser: pointer disclosure in sqlite [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported vers
Bugzilla
CVE-2017-7000 sqlite2: chromium-browser: pointer disclosure in sqlite [fedora-all]
bugzilla·2017-08-07·CVSS 8.8
CVE-2017-7000 [HIGH] CVE-2017-7000 sqlite2: chromium-browser: pointer disclosure in sqlite [fedora-all]
CVE-2017-7000 sqlite2: chromium-browser: pointer disclosure in sqlite [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported ver
Bugzilla
CVE-2017-7000 mingw-sqlite: chromium-browser: pointer disclosure in sqlite [fedora-all]
bugzilla·2017-08-07·CVSS 8.8
CVE-2017-7000 [HIGH] CVE-2017-7000 mingw-sqlite: chromium-browser: pointer disclosure in sqlite [fedora-all]
CVE-2017-7000 mingw-sqlite: chromium-browser: pointer disclosure in sqlite [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supporte
Bugzilla
chromium: various flaws [fedora-all]
bugzilla·2017-07-26·CVSS 8.8
[HIGH] chromium: various flaws [fedora-all]
chromium: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. While only
one tracking bug has b
Bugzilla
CVE-2017-7000 chromium-browser: pointer disclosure in sqlite
bugzilla·2017-07-26·CVSS 8.8
CVE-2017-7000 [HIGH] CVE-2017-7000 chromium-browser: pointer disclosure in sqlite
CVE-2017-7000 chromium-browser: pointer disclosure in sqlite
A pointer disclosure flaw was found in the SQLite component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=742407
External References:
https://chromereleases.googleblog.com/2017/07/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: fedora-all [bug 1475216]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2017:1833 https://access.redhat.com/errata/RHSA-2017:1833
---
The chromium bug is private, but looking at the commit:
https://chromium.googlesource.com/chromium/src.git/+/3bfe67c9c4b45eb713326aae7a67c8f7390dae08
Which leads to the upstream commit at:
http://www.securityfocus.com/bid/98767http://www.securityfocus.com/bid/99950https://access.redhat.com/errata/RHSA-2017:1833https://security.gentoo.org/glsa/201709-15https://support.apple.com/HT207797https://support.apple.com/HT207798https://www.debian.org/security/2017/dsa-3926http://www.securityfocus.com/bid/98767http://www.securityfocus.com/bid/99950https://access.redhat.com/errata/RHSA-2017:1833https://security.gentoo.org/glsa/201709-15https://support.apple.com/HT207797https://support.apple.com/HT207798https://www.debian.org/security/2017/dsa-3926
2018-04-03
Published