~ubuntu-security/ubuntu-cve-tracker/master

« back to all changes in this revision

Viewing changes to active/CVE-2017-5120

  • Committer: Steve Beattie
  • Date: 2019-02-19 06:18:27 UTC
  • Revision ID: sbeattie@ubuntu.com-20190219061827-oh57fzcfc1u9dlfk
The ubuntu-cve-tracker project has been converted to git.

Please use 'git clone https://git.launchpad.net/ubuntu-cve-tracker' to
get the converted tree.

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
 
Candidate: CVE-2017-5120
2
 
PublicDate: 2017-10-27
3
 
References:
4
 
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5120
5
 
 https://chromereleases.googleblog.com/2017/09/stable-channel-update-for-desktop.html
6
 
Description:
7
 
 Inappropriate use of www mismatch redirects in browser navigation in Google
8
 
 Chrome prior to 61.0.3163.79 for Mac, Windows, and Linux, and 61.0.3163.81
9
 
 for Android, allowed a remote attacker to potentially downgrade HTTPS
10
 
 requests to HTTP via a crafted HTML page. In other words, Chrome could
11
 
 transmit cleartext even though the user had entered an https URL, because
12
 
 of a misdesigned workaround for cases where the domain name in a URL almost
13
 
 matches the domain name in an X.509 server certificate (but differs in the
14
 
 initial "www." substring).
15
 
Ubuntu-Description:
16
 
Notes:
17
 
Bugs:
18
 
Priority: medium
19
 
Discovered-by: Xiaoyin Liu
20
 
Assigned-to:
21
 
 
22
 
Patches_chromium-browser:
23
 
upstream_chromium-browser: released (61.0.3163.79)
24
 
precise/esm_chromium-browser: DNE
25
 
trusty_chromium-browser: released (61.0.3163.100-0ubuntu0.14.04.1202)
26
 
vivid/ubuntu-core_chromium-browser: DNE
27
 
xenial_chromium-browser: released (61.0.3163.100-0ubuntu0.16.04.1306)
28
 
zesty_chromium-browser: released (61.0.3163.100-0ubuntu0.17.04.1377)
29
 
artful_chromium-browser: released (61.0.3163.100-0ubuntu1.1378)
30
 
bionic_chromium-browser: released (61.0.3163.100-0ubuntu1.1378)
31
 
devel_chromium-browser: released (61.0.3163.100-0ubuntu1.1378)
32
 
 
33
 
Patches_oxide-qt:
34
 
upstream_oxide-qt: needs-triage
35
 
precise/esm_oxide-qt: DNE
36
 
trusty_oxide-qt: needed
37
 
vivid/ubuntu-core_oxide-qt: DNE
38
 
xenial_oxide-qt: needs-triage
39
 
zesty_oxide-qt: ignored (reached end-of-life)
40
 
artful_oxide-qt: needs-triage
41
 
bionic_oxide-qt: DNE
42
 
devel_oxide-qt: DNE