Information disclosure in Google Chrome - CVE-2017-7000

 

Information disclosure in Google Chrome - CVE-2017-7000

Published: August 1, 2017 / Updated: June 11, 2021


Vulnerability identifier: #VU7638
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-7000
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to obtain potentially sensitive information on the system.

The weakness exists due to pointer disclosure in SQLite. A remote attacker can trick the victim into visiting a specially crafted web page and read arbitrary files on the system.

Successful exploitation of the vulnerability results in information disclosure.

Affected software

Google Chrome
Gentoo Linux
Arch Linux
Debian Linux
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Fedora
sqlite
spatialite-tools
chromium

How to mitigate CVE-2017-7000

Update to version 60.0.3112.78.

Google Chrome - update to 60.0.3112.78
sqlite - addressed in versions 3.14.2-3.fc25, 3.20.0-1.fc26
spatialite-tools - update to 4.3.0-24.fc26
chromium - addressed in versions 60.0.3112.90-1.fc25, 60.0.3112.90-1.fc26, 60.0.3112.90-3.el7, 60.0.3112.101-1.fc25, 60.0.3112.101-2.el7, 60.0.3112.113-1.fc25, 60.0.3112.113-2.el7

External References

Related Security Bulletins