CVE-2016-5202Incorrect Permission Assignment in Google Chrome

Severity
9.1CRITICALNVD
OSV8.8
EPSS
0.1%
top 65.10%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 25
Latest updateMay 24

Description

browser/extensions/api/dial/dial_registry.cc in Google Chrome before 54.0.2840.98 on macOS, before 54.0.2840.99 on Windows, and before 54.0.2840.100 on Linux neglects to copy a device ID before an erase() call, which causes the erase operation to access data that that erase operation will destroy.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NExploitability: 3.9 | Impact: 5.2

Affected Packages3 packages

NVDgoogle/chrome< 54.0.2840.98+2
Ubuntuchromium-browser/chromium-browser< 58.0.3029.81-0ubuntu0.14.04.1172+1
CVEListV5chromium-browser/chromium-browserbefore 54.0.2840.100

🔴Vulnerability Details

3
GHSA
GHSA-mwf3-rpq5-x552: browser/extensions/api/dial/dial_registry2022-05-24
OSV
oxide-qt vulnerabilities2016-12-01
OSV
CVE-2016-5202: browser/extensions/api/dial/dial_registry2016-11-11

📋Vendor Advisories

2
Ubuntu
Oxide vulnerabilities2016-12-01
Red Hat
chromium-browser: various fixes from internal audits2016-11-09

💬Community

2
Bugzilla
CVE-2016-5202 chromium-browser: various fixes from internal audits2016-11-10
Bugzilla
CVE-2016-5199 CVE-2016-5200 CVE-2016-5201 CVE-2016-5202 chromium: various flaws [fedora-all]2016-11-10