CVE-2017-15389
published 2018-02-07CVE-2017-15389: An insufficient watchdog timer in navigation in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to spoof the contents of the Omnibox (URL bar)…
PriorityP428medium6.5CVSS 3.0
AVNACLPRNUIRSUCNIHAN
EPSS
1.33%
68.3th percentile
An insufficient watchdog timer in navigation in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| chrome | < 62.0.3202.62 | 62.0.3202.62 |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jgm4-5pgf-mjm3: An insufficient watchdog timer in navigation in Google Chrome prior to 62
ghsa_unreviewed·2022-05-14
CVE-2017-15389 [MEDIUM] CWE-20 GHSA-jgm4-5pgf-mjm3: An insufficient watchdog timer in navigation in Google Chrome prior to 62
An insufficient watchdog timer in navigation in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
OSV
CVE-2017-15389: An insufficient watchdog timer in navigation in Google Chrome prior to 62
osv·2018-02-07·CVSS 6.5
CVE-2017-15389 [MEDIUM] CVE-2017-15389: An insufficient watchdog timer in navigation in Google Chrome prior to 62
An insufficient watchdog timer in navigation in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
Red Hat
chromium-browser: url spoofing in omnibox
vendor_redhat·2017-10-17·CVSS 6.5
CVE-2017-15389 [MEDIUM] chromium-browser: url spoofing in omnibox
chromium-browser: url spoofing in omnibox
An insufficient watchdog timer in navigation in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-15386 CVE-2017-15387 CVE-2017-15388 CVE-2017-15389 CVE-2017-15390 CVE-2017-15391 CVE-2017-15392 CVE-2017-15393 CVE-2017-15394 CVE-2017-15395 CVE-2017-5124 CVE-2017-5125 CVE-2017-5126 CVE-2017
bugzilla·2017-10-18·CVSS 6.5
CVE-2017-15386 [MEDIUM] CVE-2017-15386 CVE-2017-15387 CVE-2017-15388 CVE-2017-15389 CVE-2017-15390 CVE-2017-15391 CVE-2017-15392 CVE-2017-15393 CVE-2017-15394 CVE-2017-15395 CVE-2017-5124 CVE-2017-5125 CVE-2017-5126 CVE-2017
CVE-2017-15386 CVE-2017-15387 CVE-2017-15388 CVE-2017-15389 CVE-2017-15390 CVE-2017-15391 CVE-2017-15392 CVE-2017-15393 CVE-2017-15394 CVE-2017-15395 CVE-2017-5124 CVE-2017-5125 CVE-2017-5126 CVE-2017-5127 ... chromium: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant t
Bugzilla
CVE-2017-15389 chromium-browser: url spoofing in omnibox
bugzilla·2017-10-18·CVSS 6.5
CVE-2017-15389 [MEDIUM] CVE-2017-15389 chromium-browser: url spoofing in omnibox
CVE-2017-15389 chromium-browser: url spoofing in omnibox
An url spoofing flaw was found in the OmniBox component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=739621
External References:
https://chromereleases.googleblog.com/2017/10/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: fedora-all [bug 1503551]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2017:2997 https://access.redhat.com/errata/RHSA-2017:2997
http://www.securityfocus.com/bid/101482https://access.redhat.com/errata/RHSA-2017:2997https://chromereleases.googleblog.com/2017/10/stable-channel-update-for-desktop.htmlhttps://crbug.com/739621https://security.gentoo.org/glsa/201710-24https://www.debian.org/security/2017/dsa-4020http://www.securityfocus.com/bid/101482https://access.redhat.com/errata/RHSA-2017:2997https://chromereleases.googleblog.com/2017/10/stable-channel-update-for-desktop.htmlhttps://crbug.com/739621https://security.gentoo.org/glsa/201710-24https://www.debian.org/security/2017/dsa-4020
2018-02-07
Published