PublicDateAtUSN: 2017-12-07 Candidate: CVE-2017-15422 PublicDate: 2018-08-28 19:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-15422 https://chromereleases.googleblog.com/2017/12/stable-channel-update-for-desktop.html https://ubuntu.com/security/notices/USN-3610-1 Description: Integer overflow in international date handling in International Components for Unicode (ICU) for C/C++ before 60.1, as used in V8 in Google Chrome prior to 63.0.3239.84 and other products, allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. Ubuntu-Description: Notes: leosilva> same as wheezy, precise/esm is not affected code is not present. Bugs: https://code.google.com/p/chromium/issues/detail?id=774382 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H [6.5 MEDIUM] Patches_icu: upstream: http://bugs.icu-project.org/trac/changeset/40654 upstream_icu: needs-triage precise/esm_icu: not-affected (code not present) trusty_icu: released (52.1-3ubuntu0.8) trusty/esm_icu: released (52.1-3ubuntu0.8) xenial_icu: released (55.1-7ubuntu0.4) esm-infra/xenial_icu: released (55.1-7ubuntu0.4) zesty_icu: ignored (reached end-of-life) artful_icu: released (57.1-6ubuntu0.3) bionic_icu: not-affected (60.2-3ubuntu3) cosmic_icu: not-affected (60.2-3ubuntu3) devel_icu: not-affected (60.2-3ubuntu3) Patches_chromium-browser: upstream_chromium-browser: released (63.0.3239.84) precise/esm_chromium-browser: DNE trusty_chromium-browser: released (63.0.3239.84-0ubuntu0.14.04.1) trusty/esm_chromium-browser: DNE (trusty was released [63.0.3239.84-0ubuntu0.14.04.1]) xenial_chromium-browser: released (63.0.3239.84-0ubuntu0.16.04.1) zesty_chromium-browser: released (63.0.3239.84-0ubuntu0.17.04.1) artful_chromium-browser: released (63.0.3239.84-0ubuntu0.17.10.1) bionic_chromium-browser: released (63.0.3239.84-0ubuntu1) cosmic_chromium-browser: released (63.0.3239.84-0ubuntu1) devel_chromium-browser: released (63.0.3239.84-0ubuntu1) Patches_oxide-qt: upstream_oxide-qt: needs-triage precise/esm_oxide-qt: DNE trusty_oxide-qt: ignored (Ubuntu touch end-of-life) trusty/esm_oxide-qt: DNE (trusty was ignored [Ubuntu touch end-of-life]) xenial_oxide-qt: ignored (Ubuntu touch end-of-life) esm-infra/xenial_oxide-qt: ignored (Ubuntu touch end-of-life) zesty_oxide-qt: ignored (reached end-of-life) artful_oxide-qt: ignored (reached end-of-life) bionic_oxide-qt: DNE cosmic_oxide-qt: DNE devel_oxide-qt: DNE