CVE-2017-15422: Input Validation
An integer overflow flaw was found in the ICU component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=774382
External References:
https://chromereleases.googleblog.com/2017/12/stable-channel-update-for-desktop.html
Other sources
ICU. An integer overflow was addressed through improved input validation.
Integer overflow in international date handling in International Components for Unicode (ICU) allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
— IBM
Integer overflow in international date handling in International Components for Unicode (ICU) for C/C++ before 60.1, as used in V8 in Google Chrome prior to 63.0.3239.84 and other products, allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
Credit
Affected Software
Remediation
Patch Available
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2017-13887
- CVE-2017-9798
- CVE-2017-13905
- CVE-2017-7172
- CVE-2017-13892
- CVE-2017-7171
- CVE-2017-7151
- CVE-2017-1000254
- CVE-2017-13872
- CVE-2017-15422
- CVE-2017-13883
- CVE-2017-7163
- CVE-2017-7155
- CVE-2017-13878
- CVE-2017-13875
- CVE-2017-7159
- CVE-2017-13848
- CVE-2017-13858
- CVE-2017-13847
- CVE-2017-7162
- CVE-2017-13904
- CVE-2017-5754
- CVE-2017-13862
- CVE-2017-13867
- CVE-2017-7173
- CVE-2017-13876
- CVE-2017-13855
- CVE-2017-13865
- CVE-2017-13868
- CVE-2017-13869
- CVE-2017-7154
- CVE-2017-13871
- CVE-2017-13860
- CVE-2017-3735
- CVE-2017-12837
- CVE-2017-7158
- CVE-2017-13911
- CVE-2017-13886
- CVE-2017-13864
- CVE-2017-13885
- CVE-2017-7165
- CVE-2017-13884
- CVE-2017-7156
- CVE-2017-7157
- CVE-2017-13856
- CVE-2017-13870
- CVE-2017-7160
- CVE-2017-13866
- CVE-2017-7153
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2017-15422.
What is the severity of CVE-2017-15422?
The severity of CVE-2017-15422 is medium (6.5).
Which software products are affected by CVE-2017-15422?
The software products affected by CVE-2017-15422 include Google Chrome, ICU, macOS High Sierra, Sierra, El Capitan, and Ubuntu Chromium browser, among others.
How can a remote attacker exploit CVE-2017-15422?
A remote attacker can exploit CVE-2017-15422 by using a crafted HTML page to perform an out of bounds memory read.
Where can I find more information about CVE-2017-15422?
You can find more information about CVE-2017-15422 at the following references: [link1], [link2], [link3].