Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-5029

Опубликовано: 09 мар. 2017
Источник: redhat
CVSS3: 8.8
EPSS Низкий

Описание

The xsltAddTextString function in transform.c in libxslt 1.1.29, as used in Blink in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android, lacked a check for integer overflow during a size calculation, which allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page.

Дополнительная информация

Статус:

Important
https://bugzilla.redhat.com/show_bug.cgi?id=1431033chromium-browser: integer overflow in libxslt

EPSS

Процентиль: 85%
0.02374
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
почти 9 лет назад

The xsltAddTextString function in transform.c in libxslt 1.1.29, as used in Blink in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android, lacked a check for integer overflow during a size calculation, which allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page.

CVSS3: 8.8
nvd
почти 9 лет назад

The xsltAddTextString function in transform.c in libxslt 1.1.29, as used in Blink in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android, lacked a check for integer overflow during a size calculation, which allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page.

CVSS3: 8.8
debian
почти 9 лет назад

The xsltAddTextString function in transform.c in libxslt 1.1.29, as us ...

CVSS3: 8.8
github
больше 7 лет назад

Nokogiri implementation of libxslt lacks integer overflow checks

suse-cvrf
больше 8 лет назад

Security update for libxslt

EPSS

Процентиль: 85%
0.02374
Низкий

8.8 High

CVSS3