CVE-2017-5018 Information

Description

Google Chrome prior to 56.0.2924.76 for Linux Windows and Mac and 56.0.2924.87 for Android had an insufficiently strict content security policy on the Chrome app launcher page which allowed a remote attacker to inject scripts or HTML into a privileged page via a crafted HTML page.

CVSS Vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Reference

http://rhn.redhat.com/errata/RHSA-2017-0206.html http://www.debian.org/security/2017/dsa-3776 http://www.securityfocus.com/bid/95792 http://www.securitytracker.com/id/1037718 https://chromereleases.googleblog.com/2017/01/stable-channel-update-for-desktop.html https://crbug.com/668665 https://security.gentoo.org/glsa/201701-66

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

REQUIRED

Confidentiality Impact

CHANGED

Integrity Impact

LOW

Availability Impact

LOW

Base Score

NONE

Base Severity

6.1

Share on: