CVE-2017-0553
Published: 7 April 2017
An elevation of privilege vulnerability in libnl could enable a local malicious application to execute arbitrary code within the context of the Wi-Fi service. This issue is rated as Moderate because it first requires compromising a privileged process and is mitigated by current platform configurations. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-32342065. NOTE: this issue also exists in the upstream libnl before 3.3.0 library.
Notes
Author | Note |
---|---|
seth-arnold | I'm not sure this fix is strictly a security fix; the checkin comment gives me the impression callers are completely trusted. |
Priority
Status
Package | Release | Status |
---|---|---|
libnl Launchpad, Ubuntu, Debian |
artful |
Does not exist
|
bionic |
Does not exist
|
|
cosmic |
Does not exist
|
|
disco |
Does not exist
|
|
precise |
Released
(1.1-7+deb7u1build0.12.04.1)
|
|
trusty |
Does not exist
(trusty was needed)
|
|
upstream |
Needed
|
|
xenial |
Does not exist
|
|
yakkety |
Does not exist
|
|
zesty |
Does not exist
|
|
Patches: upstream: http://git.infradead.org/users/tgr/libnl.git/commit/3e18948f17148e6a3c4255bdeaaf01ef6081ceeb |
||
libnl3 Launchpad, Ubuntu, Debian |
artful |
Released
(3.2.29-0ubuntu3)
|
bionic |
Released
(3.2.29-0ubuntu3)
|
|
cosmic |
Released
(3.2.29-0ubuntu3)
|
|
disco |
Released
(3.2.29-0ubuntu3)
|
|
precise |
Ignored
(reached end-of-life)
|
|
trusty |
Released
(3.2.21-1ubuntu4.1)
|
|
upstream |
Released
(3.2.27-2)
|
|
xenial |
Released
(3.2.27-1ubuntu0.16.04.1)
|
|
yakkety |
Released
(3.2.27-1ubuntu0.16.10.1)
|
|
zesty |
Released
(3.2.29-0ubuntu2.1)
|
|
Patches: upstream: http://git.infradead.org/users/tgr/libnl.git/commit/3e18948f17148e6a3c4255bdeaaf01ef6081ceeb |
Severity score breakdown
Parameter | Value |
---|---|
Base score | 7.0 |
Attack vector | Local |
Attack complexity | High |
Privileges required | None |
User interaction | Required |
Scope | Unchanged |
Confidentiality | High |
Integrity impact | High |
Availability impact | High |
Vector | CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H |