CRITICAL
An elevation of privilege vulnerability in the Android framework (ui framework)
Published Oct 3, 2017
9.8
CRITICALCVSS 3.0
EPSS 1.85%
Description
An elevation of privilege vulnerability in the Android framework (ui framework). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-35056974.
Affected products
-
- Version 5.1.1StatusaffectedConstraints-
- Version 6.0StatusaffectedConstraints-
- Version 6.0.1StatusaffectedConstraints-
- Version 7.0StatusaffectedConstraints-
- Version 7.1.1StatusaffectedConstraints-
- Version 7.1.2StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Google Inc. | Android | n/a |
|
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (0)
No CWE recorded.
References (4)
- http://www.securityfocus.com/bid/101190 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/102131 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://source.android.com/security/bulletin/2017-12-01 x_refsource_CONFIRMVendor Advisory
- https://source.android.com/security/bulletin/pixel/2017-10-01 x_refsource_CONFIRMVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| http://www.securityfocus.com/bid/101190 | vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry | |
| http://www.securityfocus.com/bid/102131 | vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry | |
| https://source.android.com/security/bulletin/2017-12-01 | x_refsource_CONFIRMVendor Advisory | |
| https://source.android.com/security/bulletin/pixel/2017-10-01 | x_refsource_CONFIRMVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner google_android
Published Oct 3, 2017
Updated Sep 17, 2024
Reserved Nov 29, 2016
Link CVE-2017-0807
CISA Vulnrichment
Updated n/a