CVE-2017-5125
published 2018-02-07CVE-2017-5125: Heap buffer overflow in Skia in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
PriorityP343high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
1.70%
74.9th percentile
Heap buffer overflow in Skia in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| chrome | < 62.0.3202.62 | 62.0.3202.62 |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6r85-jfxp-gprw: Heap buffer overflow in Skia in Google Chrome prior to 62
ghsa_unreviewed·2022-05-14
CVE-2017-5125 [HIGH] CWE-119 GHSA-6r85-jfxp-gprw: Heap buffer overflow in Skia in Google Chrome prior to 62
Heap buffer overflow in Skia in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
OSV
CVE-2017-5125: Heap buffer overflow in Skia in Google Chrome prior to 62
osv·2018-02-07·CVSS 8.8
CVE-2017-5125 [HIGH] CVE-2017-5125: Heap buffer overflow in Skia in Google Chrome prior to 62
Heap buffer overflow in Skia in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Red Hat
chromium-browser: heap overflow in skia
vendor_redhat·2017-10-17·CVSS 8.8
CVE-2017-5125 [HIGH] chromium-browser: heap overflow in skia
chromium-browser: heap overflow in skia
Heap buffer overflow in Skia in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-15386 CVE-2017-15387 CVE-2017-15388 CVE-2017-15389 CVE-2017-15390 CVE-2017-15391 CVE-2017-15392 CVE-2017-15393 CVE-2017-15394 CVE-2017-15395 CVE-2017-5124 CVE-2017-5125 CVE-2017-5126 CVE-2017
bugzilla·2017-10-18·CVSS 6.5
CVE-2017-15386 [MEDIUM] CVE-2017-15386 CVE-2017-15387 CVE-2017-15388 CVE-2017-15389 CVE-2017-15390 CVE-2017-15391 CVE-2017-15392 CVE-2017-15393 CVE-2017-15394 CVE-2017-15395 CVE-2017-5124 CVE-2017-5125 CVE-2017-5126 CVE-2017
CVE-2017-15386 CVE-2017-15387 CVE-2017-15388 CVE-2017-15389 CVE-2017-15390 CVE-2017-15391 CVE-2017-15392 CVE-2017-15393 CVE-2017-15394 CVE-2017-15395 CVE-2017-5124 CVE-2017-5125 CVE-2017-5126 CVE-2017-5127 ... chromium: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant t
Bugzilla
CVE-2017-5125 chromium-browser: heap overflow in skia
bugzilla·2017-10-18·CVSS 8.8
CVE-2017-5125 [HIGH] CVE-2017-5125 chromium-browser: heap overflow in skia
CVE-2017-5125 chromium-browser: heap overflow in skia
A heap overflow flaw was found in the Skia component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=749147
External References:
https://chromereleases.googleblog.com/2017/10/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: fedora-all [bug 1503551]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2017:2997 https://access.redhat.com/errata/RHSA-2017:2997
http://www.securityfocus.com/bid/101482https://access.redhat.com/errata/RHSA-2017:2997https://chromereleases.googleblog.com/2017/10/stable-channel-update-for-desktop.htmlhttps://crbug.com/749147https://security.gentoo.org/glsa/201710-24https://www.debian.org/security/2017/dsa-4020http://www.securityfocus.com/bid/101482https://access.redhat.com/errata/RHSA-2017:2997https://chromereleases.googleblog.com/2017/10/stable-channel-update-for-desktop.htmlhttps://crbug.com/749147https://security.gentoo.org/glsa/201710-24https://www.debian.org/security/2017/dsa-4020
2018-02-07
Published