CVE-2017-5029 is a critical integer overflow vulnerability in the libxslt library, specifically within the xsltAddTextString function, affecting Google Chrome versions prior to 57.0.2987.98 on Mac, Windows, and Linux, and 57.0.2987.108 on Android, as well as other products utilizing libxslt 1.1.29. This flaw allows a remote attacker to achieve an out-of-bounds memory write by enticing a user to visit a specially crafted HTML page. With a CVSS score of 8.8 (High), the vulnerability presents a significant risk due to its network-based attack vector, low attack complexity, and high potential for confidentiality, integrity, and availability impacts. While there is no evidence of active exploitation, nor publicly available exploit code in Metasploit or ExploitDB, the vulnerability has garnered some community discussion and media coverage, indicating awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 57.0.2987.75CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
<= 57.0.2987.100CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
1.1.29CPE matchmatch criteria | cpe:2.3:a:xmlsoft:libxslt:1.1.29:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.