IT

Tracker / CVE-2017-5029

CVE-2017-5029

High 8.8

The xsltAddTextString function in transform.c in libxslt 1.1.29, as used in Blink in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android, lacked a check for integer overflow during a size calculation, which allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page.

Affected products and versions

debian debian_linux
google chrome · … → 57.0.2987.100
google chrome · … → 57.0.2987.75
redhat enterprise_linux_desktop
redhat enterprise_linux_server
redhat enterprise_linux_workstation
xmlsoft libxslt

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References