Use-after-free in Google Chrome - CVE-2017-5058
Published: April 20, 2017 / Updated: June 11, 2021
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a use-after-free error in Print Preview. A remote attacker can trigger heap-based buffer overflow and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
Affected software
Arch Linux
Fedora
Gentoo www-client/chromium
chromium-native_client
chromium
How to mitigate CVE-2017-5058
chromium-native_client - addressed in versions 58.0.3029.81-1.20170421gitc948e9b.fc25, 58.0.3029.81-1.20170421gitc948e9b.fc26
chromium - addressed in versions 58.0.3029.110-2.el7, 58.0.3029.110-2.fc25, 58.0.3029.110-2.fc26
External References
Related Security Bulletins
- Multiple vulnerabilities in Google Chrome
- Gentoo update for Chromium
- Arch Linux update for chromium
- OpenSUSE Linux update for chromium
- OpenSUSE Linux update for chromium
- Fedora 25 update for chromium, chromium-native_client
- Fedora 26 update for chromium, chromium-native_client
- Fedora EPEL 7 update for chromium