CVE-2017-5053
Google Chrome Array indexOf Out-Of-Bounds Access Remote Code Execution Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An out-of-bounds read in V8 in Google Chrome prior to 57.0.2987.133 for Linux, Windows, and Mac, and 57.0.2987.132 for Android, allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page, related to Array.prototype.indexOf.
Una lectura fuera de límites en V8 en Google Chrome, en versiones anteriores a la 57.0.2987.133 para Linux, Windows y Mac y a la 57.0.2987.132 para Android, permitía que un atacante remoto ejecutase código arbitrario en un espacio aislado o sandbox mediante una página HTML manipulada. Esto está relacionado con Array.prototype.indexOf.
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Google Chrome. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists within the handling of the Array.prototype.indexOf method. By performing actions in JavaScript, an attacker can trigger a memory access past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code under the context of the current process.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-01-02 CVE Reserved
- 2017-03-31 CVE Published
- 2024-08-05 CVE Updated
- 2024-09-29 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-125: Out-of-bounds Read
CAPEC
References (8)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/97220 | Vdb Entry | |
http://zerodayinitiative.com/advisories/ZDI-17-462 | X_refsource_misc | |
https://chromereleases.googleblog.com/2017/03/stable-channel-update-for-desktop_29.html | X_refsource_misc | |
https://crbug.com/702058 | X_refsource_misc |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://access.redhat.com/errata/RHSA-2017:0860 | 2023-11-07 | |
https://security.gentoo.org/glsa/201704-02 | 2023-11-07 | |
https://access.redhat.com/security/cve/CVE-2017-5053 | 2017-03-31 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1437353 | 2017-03-31 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | < 57.0.2987.133 Search vendor "Google" for product "Chrome" and version " < 57.0.2987.133" | - |
Affected
| in | Apple Search vendor "Apple" | Macos Search vendor "Apple" for product "Macos" | - | - |
Safe
|
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | < 57.0.2987.133 Search vendor "Google" for product "Chrome" and version " < 57.0.2987.133" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | - | - |
Safe
|
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | < 57.0.2987.133 Search vendor "Google" for product "Chrome" and version " < 57.0.2987.133" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | - | - |
Safe
|
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | < 57.0.2987.132 Search vendor "Google" for product "Chrome" and version " < 57.0.2987.132" | - |
Affected
| in | Google Search vendor "Google" | Android Search vendor "Google" for product "Android" | - | - |
Safe
|
Redhat Search vendor "Redhat" | Enterprise Linux Desktop Search vendor "Redhat" for product "Enterprise Linux Desktop" | 6.0 Search vendor "Redhat" for product "Enterprise Linux Desktop" and version "6.0" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Server Search vendor "Redhat" for product "Enterprise Linux Server" | 6.0 Search vendor "Redhat" for product "Enterprise Linux Server" and version "6.0" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Workstation Search vendor "Redhat" for product "Enterprise Linux Workstation" | 6.0 Search vendor "Redhat" for product "Enterprise Linux Workstation" and version "6.0" | - |
Affected
|