Candidate: CVE-2017-5028 PublicDate: 2019-06-27 17:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5028 https://chromereleases.googleblog.com/2017/01/stable-channel-update-for-desktop.html https://crbug.com/653555 Description: Insufficient data validation in V8 in Google Chrome prior to 56.0.2924.76 allowed a remote attacker to leak cross-origin data via a crafted HTML page. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N [6.5 MEDIUM] Patches_chromium-browser: upstream_chromium-browser: released (56.0.2924.76) precise/esm_chromium-browser: DNE trusty_chromium-browser: ignored (out of standard support) trusty/esm_chromium-browser: DNE xenial_chromium-browser: not-affected (74.0.3729.169-0ubuntu0.16.04.1) bionic_chromium-browser: not-affected (74.0.3729.169-0ubuntu0.16.04.1) cosmic_chromium-browser: not-affected (74.0.3729.169-0ubuntu0.16.04.1) disco_chromium-browser: not-affected (74.0.3729.169-0ubuntu0.16.04.1) devel_chromium-browser: not-affected (74.0.3729.169-0ubuntu0.16.04.1)