First published: Tue Jan 02 2018(Updated: )
Electron version 1.7.0 - 1.7.5 is vulnerable to a URL Spoofing problem when opening PDFs in PDFium resulting loading arbitrary PDFs that a hacker can control.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
npm/Electron | >=1.7.0<1.7.6 | 1.7.6 |
Atom Electron | >=1.6.4<=1.6.11 | |
Atom Electron | >=1.7.0<=1.7.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-1000424 is considered a moderate severity vulnerability due to the risk of URL Spoofing when opening PDFs.
To remediate CVE-2017-1000424, upgrade Electron to version 1.7.6 or later.
CVE-2017-1000424 affects Electron versions 1.7.0 to 1.7.5 and 1.6.4 to 1.6.11.
CVE-2017-1000424 enables a URL Spoofing attack that may allow a hacker to control the loading of arbitrary PDFs.
Yes, if your application uses the affected versions of Electron, it is susceptible to CVE-2017-1000424.