CVE-2017-5029

HIGH

Google Chrome < 57.0.2987.98 - Out-of-bounds Write via xsltAddTextString Integer Overflow

Title source: llm
STIX 2.1

Description

The xsltAddTextString function in transform.c in libxslt 1.1.29, as used in Blink in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android, lacked a check for integer overflow during a size calculation, which allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page.

References (7)

Core 7
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1038157
Issue Tracking x_refsource_confirm
https://crbug.com/676623
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2017/dsa-3810
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/96767
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2017-0499.html

Scores

CVSS v3 8.8
EPSS 0.0127
EPSS Percentile 79.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-787
Status published
Products (9)
debian/debian_linux 8.0
debian/debian_linux 9.0
google/chrome < 57.0.2987.75
n/a/Google Chrome prior to 57.0.2987.98 for Mac, Windows and Linux, and 57.0.2987.108 for Android Google Chrome prior to 57.0.2987.98 for Mac, Windows and Linux, and 57.0.2987.108 for Android
redhat/enterprise_linux_desktop 6.0
redhat/enterprise_linux_server 6.0
redhat/enterprise_linux_workstation 6.0
rubygems/nokogiri 0 - 1.7.2RubyGems
xmlsoft/libxslt 1.1.29
Published Apr 24, 2017
Tracked Since Feb 18, 2026