CVE-2017-5081

Lack of verification of an extension's locale folder in Google Chrome prior to 59.0.3071.86 for Mac, Windows, and Linux, and 59.0.3071.92 for Android, allowed an attacker with local write access to modify extensions by modifying extension files.
References
Link Resource
https://crbug.com/672008 Exploit Issue Tracking Patch Vendor Advisory
https://chromereleases.googleblog.com/2017/06/stable-channel-update-for-desktop.html Release Notes Vendor Advisory
https://security.gentoo.org/glsa/201706-20 Third Party Advisory VDB Entry
http://www.securitytracker.com/id/1038622 Third Party Advisory VDB Entry
http://www.securityfocus.com/bid/98861 Third Party Advisory VDB Entry
https://access.redhat.com/errata/RHSA-2017:1399 Third Party Advisory
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
OR cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:-:*:*:*:*:*:*:*

Configuration 4 (hide)

OR cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*

Information

Published : 2017-10-26 22:29

Updated : 2022-04-06 12:33


NVD link : CVE-2017-5081

Mitre link : CVE-2017-5081


JSON object : View

CWE
CWE-20

Improper Input Validation

Advertisement

dedicated server usa

Products Affected

redhat

  • enterprise_linux_desktop
  • enterprise_linux_workstation
  • enterprise_linux_server

google

  • android
  • chrome

microsoft

  • windows

apple

  • macos

linux

  • linux_kernel

debian

  • debian_linux