PublicDateAtUSN: 2017-03-10 Candidate: CVE-2017-5033 PublicDate: 2017-04-24 23:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5033 https://chromereleases.googleblog.com/2017/03/stable-channel-update-for-desktop.html https://ubuntu.com/security/notices/USN-3236-1 Description: Blink in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android failed to correctly propagate CSP restrictions to local scheme pages, which allowed a remote attacker to bypass content security policy via a crafted HTML page, related to the unsafe-inline keyword. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Nicolai Grødum Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N [4.3 MEDIUM] nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N [4.3 MEDIUM] Patches_chromium-browser: upstream_chromium-browser: released (57.0.2987.98) precise_chromium-browser: ignored precise/esm_chromium-browser: DNE (precise was ignored) trusty_chromium-browser: released (58.0.3029.81-0ubuntu0.14.04.1172) trusty/esm_chromium-browser: DNE (trusty was released [58.0.3029.81-0ubuntu0.14.04.1172]) vivid/ubuntu-core_chromium-browser: DNE vivid/stable-phone-overlay_chromium-browser: DNE xenial_chromium-browser: released (57.0.2987.98-0ubuntu0.16.04.1276) yakkety_chromium-browser: released (57.0.2987.98-0ubuntu0.16.10.1344) zesty_chromium-browser: released (57.0.2987.98-0ubuntu1.1348) devel_chromium-browser: released (57.0.2987.98-0ubuntu1.1348) Patches_oxide-qt: upstream_oxide-qt: released (1.21.5) precise_oxide-qt: DNE precise/esm_oxide-qt: DNE trusty_oxide-qt: released (1.21.5-0ubuntu0.14.04.1) trusty/esm_oxide-qt: DNE (trusty was released [1.21.5-0ubuntu0.14.04.1]) vivid/ubuntu-core_oxide-qt: DNE vivid/stable-phone-overlay_oxide-qt: ignored (reached end-of-life) xenial_oxide-qt: released (1.21.5-0ubuntu0.16.04.1) esm-infra/xenial_oxide-qt: released (1.21.5-0ubuntu0.16.04.1) yakkety_oxide-qt: released (1.21.5-0ubuntu0.16.10.1) zesty_oxide-qt: released (1.21.5-0ubuntu1) devel_oxide-qt: released (1.21.5-0ubuntu1)