CVE-2017-5130 PUBLISHED

An integer overflow in xmlmemory.c in libxml2 before 2.9.5, as used in Google Chrome prior to 62.0.3202.62 and other products, allowed a remote attacker to potentially exploit heap corruption via a crafted XML file.

EPSS 1.16% · 78.5th percentile

Risk Scores

EPSS Score
1.16%
78.5th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSchromium-browser0, 29.0.1547.65-0ubuntu2, 31.0.1650.63-0ubuntu1~20131204.1
Ubuntu:18.04:LTSlibxml22.9.4+dfsg1-5.2ubuntu1, 2.9.4+dfsg1-5.1ubuntu1, 2.9.4+dfsg1-5ubuntu2
Ubuntu:Pro:16.04:LTSlibxml22.9.3+dfsg1-1ubuntu0.7+esm7, 0, 2.9.2+zdfsg1-4
Ubuntu:16.04:LTSoxide-qt1.12.6-0ubuntu1, 1.12.7-0ubuntu1, 1.13.6-0ubuntu1
Ubuntu:16.04:LTSchromium-browser60.0.3112.78-0ubuntu0.16.04.1293, 48.0.2564.82-0ubuntu1.1222, 48.0.2564.116-0ubuntu1.1229
Ubuntu:Pro:14.04:LTSlibxml22.9.1+dfsg1-3ubuntu3, 2.9.1+dfsg1-3ubuntu4.1, 2.9.1+dfsg1-3ubuntu4.3
Ubuntu:18.04:LTSchromium-browser61.0.3163.100-0ubuntu1.1378, 0

Timeline

References

Open in Interactive Console →