Uninitialized Value Vulnerability in Google Chrome Affects Multiple Platforms
CVE-2017-5119
4.3MEDIUM
Key Information:
- Vendor
- Vendor
- CVE Published:
- 27 October 2017
Summary
A vulnerability exists in Google Chrome's Skia graphics library, where the use of an uninitialized value can be exploited. This issue enables remote attackers to potentially access sensitive information from the process memory by crafting a malicious HTML page. This flaw affects multiple operating systems, including Mac, Windows, Linux, and Android, prior to specified versions. Users are strongly advised to update their browsers to the latest versions to safeguard against this risk.
Affected Version(s)
Google Chrome prior to 61.0.3163.79 for Mac, Windows and Linux, and 61.0.3163.81 for Android Google Chrome prior to 61.0.3163.79 for Mac, Windows and Linux, and 61.0.3163.81 for Android
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved