CVE-2017-0553

An elevation of privilege vulnerability in libnl could enable a local malicious application to execute arbitrary code within the context of the Wi-Fi service. This issue is rated as Moderate because it first requires compromising a privileged process and is mitigated by current platform configurations. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-32342065. NOTE: this issue also exists in the upstream libnl before 3.3.0 library.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7 HIGH
LOCAL
HIGH
NONE
CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
google_androidCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 43%
VendorProductVersion
googleandroid
5.0
googleandroid
5.0.1
googleandroid
5.0.2
googleandroid
5.1
googleandroid
5.1.0
googleandroid
5.1.1
googleandroid
6.0
googleandroid
6.0.1
googleandroid
7.0
googleandroid
7.1.0
googleandroid
7.1.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
libnl3
bullseye
3.4.0-1
fixed
bookworm
3.7.0-0.2
fixed
sid
3.7.0-0.3
fixed
trixie
3.7.0-0.3
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libnl
disco
dne
cosmic
dne
bionic
dne
artful
dne
zesty
dne
yakkety
dne
xenial
dne
trusty
dne
precise
Fixed 1.1-7+deb7u1build0.12.04.1
released
libnl3
disco
Fixed 3.2.29-0ubuntu3
released
cosmic
Fixed 3.2.29-0ubuntu3
released
bionic
Fixed 3.2.29-0ubuntu3
released
artful
Fixed 3.2.29-0ubuntu3
released
zesty
Fixed 3.2.29-0ubuntu2.1
released
yakkety
Fixed 3.2.27-1ubuntu0.16.10.1
released
xenial
Fixed 3.2.27-1ubuntu0.16.04.1
released
trusty
Fixed 3.2.21-1ubuntu4.1
released
precise
ignored