Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-5029

Опубликовано: 24 апр. 2017
Источник: debian
EPSS Низкий

Описание

The xsltAddTextString function in transform.c in libxslt 1.1.29, as used in Blink in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android, lacked a check for integer overflow during a size calculation, which allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
chromium-browserfixed57.0.2987.98-1package
chromium-browserend-of-lifewheezypackage
libxsltfixed1.1.29-2.1package
libxsltfixed1.1.28-2+deb8u3jessiepackage

Примечания

  • Upstream fix in libxslt: https://git.gnome.org/browse/libxslt/commit/?id=08ab2774b870de1c7b5a48693df75e8154addae5

EPSS

Процентиль: 81%
0.02171
Низкий

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 9 лет назад

The xsltAddTextString function in transform.c in libxslt 1.1.29, as used in Blink in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android, lacked a check for integer overflow during a size calculation, which allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page.

CVSS3: 8.8
redhat
больше 9 лет назад

The xsltAddTextString function in transform.c in libxslt 1.1.29, as used in Blink in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android, lacked a check for integer overflow during a size calculation, which allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page.

CVSS3: 8.8
nvd
больше 9 лет назад

The xsltAddTextString function in transform.c in libxslt 1.1.29, as used in Blink in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android, lacked a check for integer overflow during a size calculation, which allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page.

CVSS3: 8.8
github
около 8 лет назад

Nokogiri implementation of libxslt lacks integer overflow checks

suse-cvrf
около 9 лет назад

Security update for libxslt

EPSS

Процентиль: 81%
0.02171
Низкий