CVE-2017-15396: Stack overflow in V8
A stack buffer overflow in NumberingSystem in International Components for Unicode (ICU) for C/C++ before 60.2, as used in V8 in Google Chrome prior to 62.0.3202.75 and other products, allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Other sources
Stack overflow flaws were found in the V8 component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=770452 https://bugs.chromium.org/p/chromium/issues/detail?id=770450
External References:
https://chromereleases.googleblog.com/2017/10/stable-channel-update-for-desktop26.html
— Red Hat
Credit
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-15396?
CVE-2017-15396 is considered a high severity vulnerability due to its potential for remote exploitation leading to heap corruption.
How do I fix CVE-2017-15396?
To fix CVE-2017-15396, update to Google Chrome version 62.0.3202.75 or later.
Which software is affected by CVE-2017-15396?
CVE-2017-15396 affects Google Chrome versions prior to 62.0.3202.75, along with ICU for C/C++ versions before 60.2.
What type of vulnerability is CVE-2017-15396?
CVE-2017-15396 is a stack buffer overflow vulnerability.
Can CVE-2017-15396 be exploited remotely?
Yes, CVE-2017-15396 can potentially be exploited remotely via a crafted HTML page.