CVE-2017-5029
24.04.2017, 23:59
The xsltAddTextString function in transform.c in libxslt 1.1.29, as used in Blink in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android, lacked a check for integer overflow during a size calculation, which allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page.Enginsight
Vendor | Product | Version |
---|---|---|
chrome | 𝑥 ≤ 57.0.2987.75 | |
chrome | 𝑥 ≤ 57.0.2987.100 | |
xmlsoft | libxslt | 1.1.29 |
debian | debian_linux | 8.0 |
debian | debian_linux | 9.0 |
redhat | enterprise_linux_desktop | 6.0 |
redhat | enterprise_linux_server | 6.0 |
redhat | enterprise_linux_workstation | 6.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|
chromium-browser |
| ||||||||||
libxslt |
| ||||||||||
oxide-qt |
|
Common Weakness Enumeration
References