CVE-2017-5133
published 2018-02-07CVE-2017-5133: Off-by-one read/write on the heap in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to corrupt memory and possibly leak information and…
PriorityP341high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
1.96%
78.4th percentile
Off-by-one read/write on the heap in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to corrupt memory and possibly leak information and potentially execute code via a crafted PDF file.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| chrome | < 62.0.3202.62 | 62.0.3202.62 |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
chromium-browser: out of bounds write in skia
vendor_redhat·2017-10-17·CVSS 8.8
CVE-2017-5133 [HIGH] chromium-browser: out of bounds write in skia
chromium-browser: out of bounds write in skia
Off-by-one read/write on the heap in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to corrupt memory and possibly leak information and potentially execute code via a crafted PDF file.
GHSA
GHSA-rxvj-92w6-px48: Off-by-one read/write on the heap in Blink in Google Chrome prior to 62
ghsa_unreviewed·2022-05-14
CVE-2017-5133 [HIGH] CWE-787 GHSA-rxvj-92w6-px48: Off-by-one read/write on the heap in Blink in Google Chrome prior to 62
Off-by-one read/write on the heap in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to corrupt memory and possibly leak information and potentially execute code via a crafted PDF file.
OSV
CVE-2017-5133: Off-by-one read/write on the heap in Blink in Google Chrome prior to 62
osv·2018-02-07·CVSS 8.8
CVE-2017-5133 [HIGH] CVE-2017-5133: Off-by-one read/write on the heap in Blink in Google Chrome prior to 62
Off-by-one read/write on the heap in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to corrupt memory and possibly leak information and potentially execute code via a crafted PDF file.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-5133 chromium-browser: out of bounds write in skia
bugzilla·2017-10-18·CVSS 8.8
CVE-2017-5133 [HIGH] CVE-2017-5133 chromium-browser: out of bounds write in skia
CVE-2017-5133 chromium-browser: out of bounds write in skia
An out of bounds write flaw was found in the Skia component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=762106
External References:
https://chromereleases.googleblog.com/2017/10/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: fedora-all [bug 1503551]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2017:2997 https://access.redhat.com/errata/RHSA-2017:2997
Talos
Vulnerability Spotlight: Google PDFium Tiff Code Execution
blogs_talos·2017-10-19·CVSS 8.8
[HIGH] Vulnerability Spotlight: Google PDFium Tiff Code Execution
## Overview
Talos is disclosing a single off-by-one read/write vulnerability found in the TIFF image decoder functionality of PDFium as used in Google Chrome up to and including version 60.0.3112.101. Google Chrome is the most widely used web browser today and a specially crafted PDF could trigger the vulnerability resulting in memory corruption, possible information leak, and potential code execution. This issue has been fixed in Google Chrome version 62.0.3202.62.
## TALOS-2017-0432
Discovered by Aleksandar Nikolic of Cisco Talos
Talos-2017-0432 / CVE-2017-5133 is an off-by-one read/write vulnerability residing in the TIFF image decoder functionality of PDFium. PDFium is an open sourced PDF renderer developed by Google and used in the Chrome web browser, online services, and other st
Talos
Vulnerability Spotlight: Google PDFium Tiff Code Execution
blogs_talos·2017-10-19·CVSS 8.8
[HIGH] Vulnerability Spotlight: Google PDFium Tiff Code Execution
## Vulnerability Spotlight: Google PDFium Tiff Code Execution
## Overview
Talos is disclosing a single off-by-one read/write vulnerability found in the TIFF image decoder functionality of PDFium as used in Google Chrome up to and including version 60.0.3112.101. Google Chrome is the most widely used web browser today and a specially crafted PDF could trigger the vulnerability resulting in memory corruption, possible information leak, and potential code execution. This issue has been fixed in Google Chrome version 62.0.3202.62 .
## TALOS-2017-0432
Discovered by Aleksandar Nikolic of Cisco Talos
Talos-2017-0432 / CVE-2017-5133 is an off-by-one read/write vulnerability residing in the TIFF image decoder functionality of PDFium. PDFium is an open sourced PDF renderer developed by Google a
arXiv
o-glasses: Visualizing x86 Code from Binary Using a 1d-CNN
arxiv_fulltext·2018-06-14
o-glasses: Visualizing x86 Code from Binary Using a 1d-CNN
o-glasses: Visualizing x86 Code from Binary Using a 1d-CNN
Yuhei Otsubo12
Akira Otsuka2
Mamoru Mimura32
Takeshi Sakaki4
Atsuhiro Goto2
National Police Agency, Tokyo, Japan
Institute of Information Security, Kanagawa, Japan
[email protected]
National Defense Academy, Kanagawa, Japan
The University of Tokyo, Tokyo, Japan
## Abstract
Malicious document files used in targeted attacks often contain a small program called shellcode.
It is often hard to prepare a runnable environment for dynamic analysis of these document files because they exploit specific vulnerabilities.
In these cases, it is necessary to identify the position of the shellcode in each document file to analyze it.
If the exploit code uses executable scripts such as JavaScript and Flash, it is not so hard to locate the s
http://www.securityfocus.com/bid/101482https://access.redhat.com/errata/RHSA-2017:2997https://chromereleases.googleblog.com/2017/10/stable-channel-update-for-desktop.htmlhttps://crbug.com/762106https://security.gentoo.org/glsa/201710-24https://www.debian.org/security/2017/dsa-4020http://www.securityfocus.com/bid/101482https://access.redhat.com/errata/RHSA-2017:2997https://chromereleases.googleblog.com/2017/10/stable-channel-update-for-desktop.htmlhttps://crbug.com/762106https://security.gentoo.org/glsa/201710-24https://www.debian.org/security/2017/dsa-4020
2018-02-07
Published