CVE-2017-5081
Summary
| CVE | CVE-2017-5081 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-10-27 05:29:00 UTC |
| Updated | 2023-11-07 02:48:00 UTC |
| Description | Lack of verification of an extension's locale folder in Google Chrome prior to 59.0.3071.86 for Mac, Windows, and Linux, and 59.0.3071.92 for Android, allowed an attacker with local write access to modify extensions by modifying extension files. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Chromium: Multiple vulnerabilities (GLSA 201706-20) — Gentoo Security |
|
security.gentoo.org |
|
| Chrome Releases: Stable Channel Update for Desktop |
MISC |
chromereleases.googleblog.com |
Release Notes, Vendor Advisory |
| Google Chrome Multiple Flaws Let Remote Users Spoof URLs, Obtain Potentially Sensitive Information, and Execute Arbitrary Code - SecurityTracker |
|
www.securitytracker.com |
|
| Google Chrome Prior to 59.0.3071.86 Multiple Security Vulnerabilities |
|
www.securityfocus.com |
|
| 672008 -
Security: Extension's verification bypass -
chromium -
Monorail |
MISC |
crbug.com |
Exploit, Third Party Advisory |
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 710498 Gentoo Linux Chromium Multiple Vulnerabilities (GLSA 201706-20)