Use-after-free in Google Chrome - CVE-2017-5062
Published: April 20, 2017 / Updated: June 11, 2021
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a use-after-free error in Chrome Apps. A remote attacker can trigger potentially exploitable browser crash.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
Affected software
Arch Linux
Fedora
Gentoo www-client/chromium
chromium-native_client
chromium
How to mitigate CVE-2017-5062
chromium-native_client - addressed in versions 58.0.3029.81-1.20170421gitc948e9b.fc25, 58.0.3029.81-1.20170421gitc948e9b.fc26
chromium - addressed in versions 58.0.3029.110-2.el7, 58.0.3029.110-2.fc25, 58.0.3029.110-2.fc26
External References
Related Security Bulletins
- Multiple vulnerabilities in Google Chrome
- Gentoo update for Chromium
- Arch Linux update for chromium
- OpenSUSE Linux update for chromium
- OpenSUSE Linux update for chromium
- Fedora 25 update for chromium, chromium-native_client
- Fedora 26 update for chromium, chromium-native_client
- Fedora EPEL 7 update for chromium