CVE-2017-5107

A timing attack in SVG rendering in Google Chrome prior to 60.0.3112.78 for Linux, Windows, and Mac allowed a remote attacker to extract pixel values from a cross-origin page being iframe'd via a crafted HTML page.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
OR cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*

Information

Published : 2017-10-27 05:29

Updated : 2021-09-08 17:21


NVD link : CVE-2017-5107

Mitre link : CVE-2017-5107


JSON object : View

Products Affected

microsoft

  • windows

apple

  • macos

linux

  • linux_kernel

google

  • chrome
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor