Cross-site scripting in Google Chrome - CVE-2017-5085
Published: June 7, 2017 / Updated: June 11, 2021
Vulnerability details
The vulnerability exists due to inappropriate execution of javascript on WebUI pages. A remote attacker can trick the victim to follow a specially specially crafted link and execute arbitrary HTML and script code in victim's browser in security context of vulnerable website.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.
Affected software
Arch Linux
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Fedora
Opensuse
chromium-native_client
chromium
How to mitigate CVE-2017-5085
chromium-native_client - addressed in versions 59.0.3071.86-1.20170607gitaac1de2.fc24, 59.0.3071.86-1.20170607gitaac1de2.fc25, 59.0.3071.86-1.20170607gitaac1de2.fc26
chromium - addressed in versions 59.0.3071.86-3.el7, 59.0.3071.104-1.el7
External References
Related Security Bulletins
- Multiple vulnerabilities in Google Chrome
- openSUSE update for chromium
- Arch Linux update for chromium
- OpenSUSE Linux update for chromium
- Red Hat update for chromium-browser
- Fedora EPEL 7 update for chromium
- Fedora 24 update for chromium-native_client
- Fedora 25 update for chromium-native_client
- Fedora 26 update for chromium-native_client
- Fedora EPEL 7 update for chromium