CVE-2017-5006

Name
CVE-2017-5006
Description
Blink in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, incorrectly handled object owner relationships, which allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
chrome-cve-admin@google.com http://rhn.redhat.com/errata/RHSA-2017-0206.html
chrome-cve-admin@google.com http://www.debian.org/security/2017/dsa-3776
chrome-cve-admin@google.com http://www.securityfocus.com/bid/95792
chrome-cve-admin@google.com http://www.securitytracker.com/id/1037718
chrome-cve-admin@google.com https://chromereleases.googleblog.com/2017/01/stable-channel-update-for-desktop.html
chrome-cve-admin@google.com https://crbug.com/673170
chrome-cve-admin@google.com https://security.gentoo.org/glsa/201701-66

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* chrome >= None <= 55.0.2883.87

Vulnerable and fixed packages

Source package Branch Version Maintainer Status