Information disclosure in Google Chrome - CVE-2017-5119

 

Information disclosure in Google Chrome - CVE-2017-5119

Published: September 7, 2017 / Updated: June 11, 2021


Vulnerability identifier: #VU8134
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-5119
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to obtain potentially sensitive information.

The weakness exists due to use of uninitialized value in Skia. A remote attacker can trick the victim into visiting a specially crafted website and read arbitrary data from system memory.

Successful exploitation of the vulnerability results in information disclosure.

Affected software

Google Chrome
Arch Linux
Gentoo Linux
Debian Linux
Red Hat Enterprise Linux for x86_64
Fedora
chromium

How to mitigate CVE-2017-5119

Update to version 61.0.

Google Chrome - update to 61.0.3163.79
chromium - addressed in versions 61.0.3163.100-1.el7, 61.0.3163.100-1.fc25, 61.0.3163.100-1.fc26, 61.0.3163.100-1.fc27, 62.0.3202.75-1.fc25, 62.0.3202.89-1.fc25

External References

Related Security Bulletins