CVE-2017-5029
Summary
| CVE | CVE-2017-5029 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-04-24 23:59:00 UTC |
| Updated | 2023-11-07 02:48:00 UTC |
| Description | The xsltAddTextString function in transform.c in libxslt 1.1.29, as used in Blink in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android, lacked a check for integer overflow during a size calculation, which allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Check for integer overflow in xsltAddTextString (08ab2774) · Commits · GNOME / libxslt · GitLab |
|
git.gnome.org |
|
| Red Hat Customer Portal |
REDHAT |
rhn.redhat.com |
|
| 676623 -
Security: libxslt generation of text nodes integer overflow -
chromium -
Monorail |
CONFIRM |
crbug.com |
Issue Tracking, Patch |
| Debian -- Security Information -- DSA-3810-1 chromium-browser |
DEBIAN |
www.debian.org |
|
| Apple iTunes for Windows Multiple Flaws Let Remote Users Obtain Potentially Sensitive Information and Execute Arbitrary Code - SecurityTracker |
SECTRACK |
www.securitytracker.com |
|
| Google Chrome Prior to 57.0.2987.98 Multiple Security Vulnerabilities |
|
www.securityfocus.com |
|
| Chrome Releases: Stable Channel Update for Desktop |
|
chromereleases.googleblog.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 500351 Alpine Linux Security Update for libxslt
- 504115 Alpine Linux Security Update for libxslt
- 710230 Gentoo Linux libxslt Multiple Vulnerabilities (GLSA 201804-01)