Information disclosure in Google Chrome - CVE-2017-5088

 

Information disclosure in Google Chrome - CVE-2017-5088

Published: June 20, 2017 / Updated: June 11, 2021


Vulnerability identifier: #VU7126
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-5088
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to obtain potentially sensitive information on the target system.

The weakness exists due to out-of-bounds read error in V8. A remote attacker can read arbitrary files that may allow to conduct further attacks.

Successful exploitation of the vulnerability results in information disclosure.

Affected software

Google Chrome
Arch Linux
Debian Linux
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Fedora
qt5-qtwebengine
chromium

How to mitigate CVE-2017-5088

Update to version 59.0.3071.104.

Google Chrome - update to 59.0.3071.104
qt5-qtwebengine - addressed in versions 5.9.1-1.fc25, 5.9.1-1.fc26
chromium - addressed in versions 59.0.3071.104-1.el7, 59.0.3071.104-1.fc24, 59.0.3071.104-1.fc25, 59.0.3071.104-1.fc26

External References

Related Security Bulletins