CVE-2017-5124
published 2018-02-07CVE-2017-5124: Incorrect application of sandboxing in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a…
PriorityP339medium6.1CVSS 3.0
AVNACLPRNUIRSCCLILAN
EXPLOIT
EPSS
5.24%
91.5th percentile
Incorrect application of sandboxing in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted MHTML page.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| chrome | < 62.0.3202.62 | 62.0.3202.62 |
CVSS provenance
nvdv3.06.1MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv6.1MEDIUM
vendor_redhat6.1MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-g2xv-2cjq-c43m: Incorrect application of sandboxing in Blink in Google Chrome prior to 62
ghsa_unreviewed·2022-05-14
CVE-2017-5124 [MEDIUM] CWE-79 GHSA-g2xv-2cjq-c43m: Incorrect application of sandboxing in Blink in Google Chrome prior to 62
Incorrect application of sandboxing in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted MHTML page.
OSV
CVE-2017-5124: Incorrect application of sandboxing in Blink in Google Chrome prior to 62
osv·2018-02-07·CVSS 6.1
CVE-2017-5124 [MEDIUM] CVE-2017-5124: Incorrect application of sandboxing in Blink in Google Chrome prior to 62
Incorrect application of sandboxing in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted MHTML page.
Red Hat
chromium-browser: uxss with mhtml
vendor_redhat·2017-10-17·CVSS 6.1
CVE-2017-5124 [MEDIUM] chromium-browser: uxss with mhtml
chromium-browser: uxss with mhtml
Incorrect application of sandboxing in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted MHTML page.
Suricata
ET WEB_CLIENT Google Chrome XSS (CVE-2017-5124)
suricata·2017-11-15·CVSS 6.1
CVE-2017-5124 [MEDIUM] ET WEB_CLIENT Google Chrome XSS (CVE-2017-5124)
ET WEB_CLIENT Google Chrome XSS (CVE-2017-5124)
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET WEB_CLIENT Google Chrome XSS (CVE-2017-5124)"; flow:established,to_client; http.content_type; content:"multipart/related"; fast_pattern; startswith; file.data; content:"[^\x22\x27]+?)[\x27\x22].+?Content-Location\x3a\s+(?P=loc)/Rsi"; reference:cve,2017-5124; classtype:attempted-user; sid:2024996; rev:7; metadata:affected_product Google_Chrome, attack_target Client_Endpoint, created_at 2017_11_15, cve CVE_2017_5124, deployment Perimeter, performance_impact Low, signature_severity Major, tag Web_Client_Attacks, updated_at 2024_03_07;)
Bugzilla
CVE-2017-5124 chromium-browser: uxss with mhtml
bugzilla·2017-10-18·CVSS 6.1
CVE-2017-5124 [MEDIUM] CVE-2017-5124 chromium-browser: uxss with mhtml
CVE-2017-5124 chromium-browser: uxss with mhtml
The following flaw was identified in the Chromium browser: uxss with mhtml.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=762930
External References:
https://chromereleases.googleblog.com/2017/10/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: fedora-all [bug 1503551]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2017:2997 https://access.redhat.com/errata/RHSA-2017:2997
Bugzilla
CVE-2017-15386 CVE-2017-15387 CVE-2017-15388 CVE-2017-15389 CVE-2017-15390 CVE-2017-15391 CVE-2017-15392 CVE-2017-15393 CVE-2017-15394 CVE-2017-15395 CVE-2017-5124 CVE-2017-5125 CVE-2017-5126 CVE-2017
bugzilla·2017-10-18·CVSS 6.5
CVE-2017-15386 [MEDIUM] CVE-2017-15386 CVE-2017-15387 CVE-2017-15388 CVE-2017-15389 CVE-2017-15390 CVE-2017-15391 CVE-2017-15392 CVE-2017-15393 CVE-2017-15394 CVE-2017-15395 CVE-2017-5124 CVE-2017-5125 CVE-2017-5126 CVE-2017
CVE-2017-15386 CVE-2017-15387 CVE-2017-15388 CVE-2017-15389 CVE-2017-15390 CVE-2017-15391 CVE-2017-15392 CVE-2017-15393 CVE-2017-15394 CVE-2017-15395 CVE-2017-5124 CVE-2017-5125 CVE-2017-5126 CVE-2017-5127 ... chromium: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant t
http://www.securityfocus.com/bid/101482https://access.redhat.com/errata/RHSA-2017:2997https://chromereleases.googleblog.com/2017/10/stable-channel-update-for-desktop.htmlhttps://chromium.googlesource.com/chromium/src/+/4558c2885e618557a674660aff57404d25537070https://crbug.com/762930https://github.com/Bo0oM/CVE-2017-5124https://security.gentoo.org/glsa/201710-24https://www.debian.org/security/2017/dsa-4020https://www.reddit.com/r/netsec/comments/7cus2h/chrome_61_uxss_exploit_cve20175124/http://www.securityfocus.com/bid/101482https://access.redhat.com/errata/RHSA-2017:2997https://chromereleases.googleblog.com/2017/10/stable-channel-update-for-desktop.htmlhttps://chromium.googlesource.com/chromium/src/+/4558c2885e618557a674660aff57404d25537070https://crbug.com/762930https://github.com/Bo0oM/CVE-2017-5124https://security.gentoo.org/glsa/201710-24https://www.debian.org/security/2017/dsa-4020https://www.reddit.com/r/netsec/comments/7cus2h/chrome_61_uxss_exploit_cve20175124/
2018-02-07
Published