Candidate: CVE-2017-15403 PublicDate: 2019-01-09 19:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-15403 https://chromereleases.googleblog.com/2017/10/stable-channel-updates-for-chrome-os.html https://crbug.com/766271 Description: Insufficient data validation in crosh could lead to a command injection under chronos privileges in Networking in Google Chrome on Chrome OS prior to 61.0.3163.113 allowed a local attacker to execute arbitrary code via a crafted HTML page. Ubuntu-Description: Notes: mdeslaur> chrome os specific Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H [7.3 HIGH] Patches_chromium-browser: upstream_chromium-browser: released precise/esm_chromium-browser: DNE trusty_chromium-browser: ignored (no longer updated) trusty/esm_chromium-browser: DNE (trusty was ignored [no longer updated]) xenial_chromium-browser: not-affected bionic_chromium-browser: not-affected cosmic_chromium-browser: ignored (reached end-of-life) disco_chromium-browser: ignored (reached end-of-life) eoan_chromium-browser: not-affected devel_chromium-browser: not-affected