CVE-2017-0208
MEDIUM4.3EPSS 14.9%ChakraCore information disclosure vulnerability
發布日:2022/5/17修改日:2024/2/16
描述
An information disclosure vulnerability exists in Microsoft Edge when the Chakra scripting engine does not properly handle objects in memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user's system, a.k.a. "Scripting Engine Information Disclosure Vulnerability."
受影響套件(1)
- NuGet/Microsoft.ChakraCorefrom 0, < 1.4.3
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM4.3 | CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N |
參考連結(7)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2017-0208
- PATCHhttps://github.com/chakra-core/ChakraCore
- WEBhttps://github.com/chakra-core/ChakraCore/commit/54d6d085987e2c399863940179db67b594d7f0a3
- WEBhttps://github.com/chakra-core/ChakraCore/pull/2834
- WEBhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0208
- WEBhttps://web.archive.org/web/20210124023848/http://www.securityfocus.com/bid/97460
- WEBhttps://web.archive.org/web/20211201121401/http://www.securitytracker.com/id/1038234