CVE-2017-5068Race Condition in Google Chrome

CWE-362Race Condition6 documents5 sources
Severity
7.5HIGHNVD
EPSS
0.4%
top 39.89%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 27
Latest updateMay 13

Description

Incorrect handling of picture ID in WebRTC in Google Chrome prior to 58.0.3029.96 for Mac, Windows, and Linux allowed a remote attacker to trigger a race condition via a crafted HTML page.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.6 | Impact: 5.9

Affected Packages4 packages

🔴Vulnerability Details

2
GHSA
GHSA-j36c-g9g3-m3ph: Incorrect handling of picture ID in WebRTC in Google Chrome prior to 582022-05-13
OSV
CVE-2017-5068: Incorrect handling of picture ID in WebRTC in Google Chrome prior to 582017-10-27

📋Vendor Advisories

1
Red Hat
chromium-browser: race condition in webrtc2017-05-02

💬Community

2
Bugzilla
CVE-2017-5068 chromium: chromium-browser: race condition in webrtc [fedora-all]2017-05-04
Bugzilla
CVE-2017-5068 chromium-browser: race condition in webrtc2017-05-04