CVE-2016-5166: Infoleak
Published Sep 11, 2016
·Updated
The download implementation in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux does not properly restrict saving a file:// URL that is referenced by an http:// URL, which makes it easier for user-assisted remote attackers to discover NetNTLM hashes and conduct SMB relay attacks via a crafted web page that is accessed with the "Save page as" menu choice.
Affected Software
2 affected components
Google Chrome<=52.0.2743.116
openSUSE Leap=42.1
Event History
Sep 11, 2016
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-5166?
CVE-2016-5166 is considered a moderate severity vulnerability.
2
How do I fix CVE-2016-5166?
To fix CVE-2016-5166, ensure you update Google Chrome to version 53.0.2785.89 or later.
3
Which versions of Google Chrome are affected by CVE-2016-5166?
CVE-2016-5166 affects Google Chrome versions before 53.0.2785.89.
4
Is openSUSE affected by CVE-2016-5166?
Yes, openSUSE Leap 42.1 is also affected by CVE-2016-5166.
5
What type of vulnerability is CVE-2016-5166 classified as?
CVE-2016-5166 is classified as a file handling vulnerability.