CVE Database
/

CVE-2017-5029

Back to search

CVE-2017-5029

Published: Apr 24, 2017

Modified: Aug 5, 2024

PUBLISHED

Description

The xsltAddTextString function in transform.c in libxslt 1.1.29, as used in Blink in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android, lacked a check for integer overflow during a size calculation, which allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page.

VendorProductVersions

n/a

Google Chrome prior to 57.0.2987.98 for Mac, Windows and Linux, and 57.0.2987.108 for Android

affected
Google Chrome prior to 57.0.2987.98 for Mac, Windows and Linux, and 57.0.2987.108 for Android

References

1038157
vdb-entry
x_refsource_SECTRACK
https://crbug.com/676623
x_refsource_CONFIRM
DSA-3810
vendor-advisory
x_refsource_DEBIAN
96767
vdb-entry
x_refsource_BID
RHSA-2017:0499
vendor-advisory
x_refsource_REDHAT

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now