CVE-2017-15423 PUBLISHED

Inappropriate implementation in BoringSSL SPAKE2 in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to leak the low-order bits of SHA512(password) by inspecting protocol traffic.

EPSS 0.60% · 69.3th percentile

Risk Scores

EPSS Score
0.60%
69.3th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSchromium-browser62.0.3202.94-0ubuntu1.1388, 62.0.3202.89-0ubuntu1.1386, 62.0.3202.62-0ubuntu0.17.10.1380
Ubuntu:14.04:LTSchromium-browser34.0.1847.116-0ubuntu2, 36.0.1985.125-0ubuntu1.14.04.0~pkg1029, 37.0.2062.94-0ubuntu0.14.04.1~pkg1042
Ubuntu:16.04:LTSoxide-qt1.16.5-0ubuntu0.16.04.1, 0, 1.9.5-0ubuntu1
Ubuntu:16.04:LTSchromium-browser62.0.3202.94-0ubuntu0.16.04.1317, 48.0.2564.82-0ubuntu1.1222, 47.0.2526.106-0ubuntu1.1221

Timeline

References

Open in Interactive Console →