CVE-2017-5075: Infoleak
An information leak flaw was found in the CSP reporting component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=678776
External References:
https://chromereleases.googleblog.com/2017/06/stable-channel-update-for-desktop.html
Other sources
Inappropriate implementation in CSP reporting in Blink in Google Chrome prior to 59.0.3071.86 for Linux, Windows, and Mac, and 59.0.3071.92 for Android, allowed a remote attacker to obtain the value of url fragments via a crafted HTML page.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-5075?
CVE-2017-5075 is classified as a medium severity vulnerability.
How do I fix CVE-2017-5075?
To fix CVE-2017-5075, you should upgrade Google Chrome to version 59.0.3071.86 or later.
Which versions of Google Chrome are affected by CVE-2017-5075?
Google Chrome versions prior to 59.0.3071.86 for Linux, Windows, and Mac, and 59.0.3071.92 for Android are affected by CVE-2017-5075.
What type of vulnerability is CVE-2017-5075?
CVE-2017-5075 is an information leak vulnerability related to CSP reporting in Google Chrome.
Can CVE-2017-5075 be exploited remotely?
Yes, CVE-2017-5075 can be exploited remotely through a crafted HTML page.