CVE-2017-5035Race Condition in Google Chrome

CWE-362Race Condition8 documents6 sources
Severity
8.1HIGHNVD
OSV8.8
EPSS
0.4%
top 37.09%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 24
Latest updateApr 30

Description

Google Chrome prior to 57.0.2987.98 for Windows and Mac had a race condition, which could cause Chrome to display incorrect certificate information for a site.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 2.2 | Impact: 5.9

Affected Packages4 packages

Also affects: Debian Linux 8.0, 9.0

🔴Vulnerability Details

3
GHSA
GHSA-pwgq-fv9q-ff77: Google Chrome prior to 572022-04-30
OSV
oxide-qt vulnerabilities2017-03-29
OSV
CVE-2017-5035: Google Chrome prior to 572017-03-10

📋Vendor Advisories

2
Ubuntu
Oxide vulnerabilities2017-03-29
Red Hat
chromium-browser: incorrect security ui in omnibox2017-03-09

💬Community

2
Bugzilla
CVE-2017-5035 chromium-browser: incorrect security ui in omnibox2017-03-10
Bugzilla
chromium: various flaws [fedora-all]2017-03-10