2024-12-08 03:06:42 +00:00

115 lines
3.7 KiB
JSON

{
"id": "CVE-2017-15405",
"sourceIdentifier": "chrome-cve-admin@google.com",
"published": "2019-01-09T19:29:00.917",
"lastModified": "2024-11-21T03:14:38.800",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Inappropriate symlink handling and a race condition in the stateful recovery feature implementation could lead to a persistance established by a malicious code running with root privileges in cryptohomed in Google Chrome on Chrome OS prior to 61.0.3163.113 allowed a local attacker to execute arbitrary code via a crafted HTML page."
},
{
"lang": "es",
"value": "La gesti\u00f3n de symlink inapropiada y una condici\u00f3n de carrera en la implementaci\u00f3n de la funcionalidad de recuperaci\u00f3n de estado podr\u00eda provocar una persistencia establecida por c\u00f3digo malicioso que se ejecuta con privilegios root en cryptohomed en Google Chrome en Chroms OS, en sus versiones anteriores a la 61.0.3163.113, permiti\u00f3 a un atacante local ejecutar c\u00f3digo arbitrario mediante una p\u00e1gina HTML manipulada."
}
],
"metrics": {
"cvssMetricV30": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.0",
"vectorString": "CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
"baseScore": 7.0,
"baseSeverity": "HIGH",
"attackVector": "LOCAL",
"attackComplexity": "HIGH",
"privilegesRequired": "LOW",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "HIGH"
},
"exploitabilityScore": 1.0,
"impactScore": 5.9
}
],
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:L/AC:M/Au:N/C:C/I:C/A:C",
"baseScore": 6.9,
"accessVector": "LOCAL",
"accessComplexity": "MEDIUM",
"authentication": "NONE",
"confidentialityImpact": "COMPLETE",
"integrityImpact": "COMPLETE",
"availabilityImpact": "COMPLETE"
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 3.4,
"impactScore": 10.0,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-362"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*",
"versionEndExcluding": "61.0.3163.113",
"matchCriteriaId": "A79C7C71-F89D-47B6-B58D-570FA10A5359"
}
]
}
]
}
],
"references": [
{
"url": "https://chromereleases.googleblog.com/2017/10/stable-channel-updates-for-chrome-os.html",
"source": "chrome-cve-admin@google.com"
},
{
"url": "https://crbug.com/766276",
"source": "chrome-cve-admin@google.com"
},
{
"url": "https://chromereleases.googleblog.com/2017/10/stable-channel-updates-for-chrome-os.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://crbug.com/766276",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
]
}