ALT-PU-2017-2656-1
Closed vulnerabilities
Published: 2018-08-28
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2017-15398
A stack buffer overflow in the QUIC networking stack in Google Chrome prior to 62.0.3202.89 allowed a remote attacker to gain code execution via a malicious server.
Severity: HIGH (7.5)
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P
Severity: CRITICAL (9.8)
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
References:
- http://www.securityfocus.com/bid/101692
- https://access.redhat.com/errata/RHSA-2017:3151
- https://chromereleases.googleblog.com/2017/11/stable-channel-update-for-desktop.html
- https://crbug.com/777728
- https://security.gentoo.org/glsa/201711-02
- https://www.debian.org/security/2017/dsa-4024
- http://www.securityfocus.com/bid/101692
- https://access.redhat.com/errata/RHSA-2017:3151
- https://chromereleases.googleblog.com/2017/11/stable-channel-update-for-desktop.html
- https://crbug.com/777728
- https://security.gentoo.org/glsa/201711-02
- https://www.debian.org/security/2017/dsa-4024
Published: 2018-08-28
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2017-15399
A use after free in V8 in Google Chrome prior to 62.0.3202.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Severity: CRITICAL (9.3)
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C
Severity: HIGH (8.8)
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
References:
- http://www.securityfocus.com/bid/101692
- https://access.redhat.com/errata/RHSA-2017:3151
- https://chromereleases.googleblog.com/2017/11/stable-channel-update-for-desktop.html
- https://crbug.com/776677
- https://security.gentoo.org/glsa/201711-02
- https://www.debian.org/security/2017/dsa-4024
- http://www.securityfocus.com/bid/101692
- https://access.redhat.com/errata/RHSA-2017:3151
- https://chromereleases.googleblog.com/2017/11/stable-channel-update-for-desktop.html
- https://crbug.com/776677
- https://security.gentoo.org/glsa/201711-02
- https://www.debian.org/security/2017/dsa-4024