CVE-2017-0386

Description

An elevation of privilege vulnerability in the libnl library could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1. Android ID: A-32255299.

Risk Information

Base Score
7.8
MODERATE
Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.138

Associated Vulnerability

VulnerabilityOS Platform
SUSE-SU-2022:3207-1(SUSE Linux Enterprise Server 12-SP5 ) libnl-1_1-debugsource-1.1.4-6.3.1.x86_64.rpmLinux
SUSE-SU-2022:3207-1(SUSE Linux Enterprise Server 12-SP5 ) libnl1-1.1.4-6.3.1.x86_64.rpmLinux
SUSE-SU-2022:3207-1(SUSE Linux Enterprise Server 12-SP5 ) libnl1-32bit-1.1.4-6.3.1.x86_64.rpmLinux
SUSE-SU-2022:3207-1(SUSE Linux Enterprise Server 12-SP5 ) libnl1-debuginfo-1.1.4-6.3.1.x86_64.rpmLinux
SUSE-SU-2022:3207-1(SUSE Linux Enterprise Server 12-SP5 ) libnl1-debuginfo-32bit-1.1.4-6.3.1.x86_64.rpmLinux
SUSE-SU-2022:3208-1(SUSE Linux Enterprise Server 12-SP5 ) libnl-config-3.2.23-4.7.1.noarch.rpmLinux
SUSE-SU-2022:3208-1(SUSE Linux Enterprise Server 12-SP5 ) libnl3-200-3.2.23-4.7.1.x86_64.rpmLinux
SUSE-SU-2022:3208-1(SUSE Linux Enterprise Server 12-SP5 ) libnl3-200-32bit-3.2.23-4.7.1.x86_64.rpmLinux
SUSE-SU-2022:3208-1(SUSE Linux Enterprise Server 12-SP5 ) libnl3-200-debuginfo-3.2.23-4.7.1.x86_64.rpmLinux
SUSE-SU-2022:3208-1(SUSE Linux Enterprise Server 12-SP5 ) libnl3-200-debuginfo-32bit-3.2.23-4.7.1.x86_64.rpmLinux
SUSE-SU-2022:3208-1(SUSE Linux Enterprise Server 12-SP5 ) libnl3-debugsource-3.2.23-4.7.1.x86_64.rpmLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234