Input validation error in Google Android - CVE-2017-0386

 

Input validation error in Google Android - CVE-2017-0386

Published: January 12, 2017 / Updated: August 8, 2020


Vulnerability identifier: #VU39832
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-0386
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

An elevation of privilege vulnerability in the libnl library could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1. Android ID: A-32255299.


Affected software

Google Android
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Software Development Kit
Fedora
Dell EMC PowerProtect Data Protection
Dell Data Protection Central
libnl-1_1-devel
libnl1
libnl1-debuginfo
libnl1-32bit
libnl1-debuginfo-32bit
libnl-1_1-debugsource
libnl3-200-debuginfo
libnl-config
libnl3-200-debuginfo-32bit
libnl3-200-32bit
libnl3-200
libnl3-devel
libnl3-debugsource
libnl3
Dell EMC NetWorker vProxy
Dell EMC Storage Monitoring and Reporting (SMR)
EMC ViPR SRM

How to mitigate CVE-2017-0386

Install update from vendor's website.

libnl-1_1-devel - update to 1.1.4-6.3.1
libnl1 - update to 1.1.4-6.3.1
libnl1-debuginfo - update to 1.1.4-6.3.1
libnl1-32bit - update to 1.1.4-6.3.1
libnl1-debuginfo-32bit - update to 1.1.4-6.3.1
libnl-1_1-debugsource - update to 1.1.4-6.3.1
libnl3-200-debuginfo - update to 3.2.23-4.7.1
libnl-config - update to 3.2.23-4.7.1
libnl3-200-debuginfo-32bit - update to 3.2.23-4.7.1
libnl3-200-32bit - update to 3.2.23-4.7.1
libnl3-200 - update to 3.2.23-4.7.1
libnl3-devel - update to 3.2.23-4.7.1
libnl3-debugsource - update to 3.2.23-4.7.1
libnl3 - addressed in versions 3.2.28-4.fc24, 3.2.29-2.fc25
Dell EMC NetWorker vProxy - update to 4.3.0-36
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.8.0.1
EMC ViPR SRM - update to 4.8.0.1

External References

Related Security Bulletins