CVE-2017-5071: Input Validation
An out of bounds read flaw was found in the V8 component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=715582
External References:
https://chromereleases.googleblog.com/2017/06/stable-channel-update-for-desktop.html
Other sources
Insufficient validation of untrusted input in V8 in Google Chrome prior to 59.0.3071.86 for Linux, Windows and Mac, and 59.0.3071.92 for Android allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-5071?
CVE-2017-5071 is classified as a high severity vulnerability due to the potential for remote exploitation via crafted HTML.
How do I fix CVE-2017-5071?
To fix CVE-2017-5071, update Google Chrome to version 59.0.3071.86 or later.
What systems are affected by CVE-2017-5071?
CVE-2017-5071 affects Google Chrome versions prior to 59.0.3071.86 on Linux, Windows, and Mac, as well as version 59.0.3071.92 on Android.
What type of vulnerability is CVE-2017-5071?
CVE-2017-5071 is an out of bounds read vulnerability identified in the V8 engine of Google Chrome.
Can CVE-2017-5071 be exploited remotely?
Yes, CVE-2017-5071 can be exploited remotely through a specially crafted HTML page.