CVE-2017-5077Out-of-bounds Read in Google Chrome

CWE-125Out-of-bounds Read6 documents5 sources
Severity
8.8HIGHNVD
EPSS
0.9%
top 24.97%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 27
Latest updateMay 13

Description

Insufficient validation of untrusted input in Skia in Google Chrome prior to 59.0.3071.86 for Linux, Windows, and Mac, and 59.0.3071.92 for Android, allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages4 packages

🔴Vulnerability Details

2
GHSA
GHSA-w37g-w82j-jjmr: Insufficient validation of untrusted input in Skia in Google Chrome prior to 592022-05-13
OSV
CVE-2017-5077: Insufficient validation of untrusted input in Skia in Google Chrome prior to 592017-10-27

📋Vendor Advisories

1
Red Hat
chromium-browser: heap buffer overflow in skia2017-06-05

💬Community

2
Bugzilla
chromium: various flaws [fedora-all]2017-06-06
Bugzilla
CVE-2017-5077 chromium-browser: heap buffer overflow in skia2017-06-06