Learn about CVE-2017-5097 affecting Google Chrome prior to version 60.0.3112.78 for Linux. Find out how remote attackers can exploit an out-of-bounds read vulnerability in Skia.
Google Chrome prior to version 60.0.3112.78 for Linux is affected by an out-of-bounds read vulnerability in Skia, allowing remote attackers to execute an out-of-bounds memory read through a manipulated HTML page.
Understanding CVE-2017-5097
Before version 60.0.3112.78 of Google Chrome for Linux, Skia had inadequate validation of untrusted input, which could enable a remote attacker to execute an out-of-bounds memory read by utilizing a manipulated HTML page.
What is CVE-2017-5097?
CVE-2017-5097 is a vulnerability in Google Chrome for Linux that allows remote attackers to perform an out-of-bounds memory read via a crafted HTML page due to insufficient validation of untrusted input in Skia.
The Impact of CVE-2017-5097
This vulnerability could be exploited by a remote attacker to execute an out-of-bounds memory read, potentially leading to unauthorized access or sensitive information exposure.
Technical Details of CVE-2017-5097
Google Chrome prior to version 60.0.3112.78 for Linux is susceptible to the following:
Vulnerability Description
The vulnerability arises from inadequate validation of untrusted input in Skia, enabling an out-of-bounds memory read.
Affected Systems and Versions
Exploitation Mechanism
The vulnerability can be exploited by a remote attacker through a manipulated HTML page, triggering an out-of-bounds memory read.
Mitigation and Prevention
To address CVE-2017-5097, consider the following steps:
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates