Your submission was sent successfully! Close

CVE-2017-5086

Published: 27 October 2017

Insufficient Policy Enforcement in Omnibox in Google Chrome prior to 59.0.3071.86 for Windows and Mac allowed a remote attacker to perform domain spoofing via IDN homographs in a crafted domain name.

Priority

Medium

CVSS 3 base score: 6.5

Status

Package Release Status
chromium-browser
Launchpad, Ubuntu, Debian
artful
Released (59.0.3071.109-0ubuntu1.1360)
bionic
Released (59.0.3071.109-0ubuntu1.1360)
cosmic
Released (59.0.3071.109-0ubuntu1.1360)
precise Does not exist

trusty Does not exist
(trusty was released [59.0.3071.109-0ubuntu0.14.04.1186])
upstream
Released (59.0.3071.86)
xenial
Released (59.0.3071.109-0ubuntu0.16.04.1289)
yakkety
Released (59.0.3071.109-0ubuntu0.16.10.1357)
zesty
Released (59.0.3071.109-0ubuntu0.17.04.1360)
oxide-qt
Launchpad, Ubuntu, Debian
artful Ignored
(reached end-of-life)
bionic Does not exist

cosmic Does not exist

precise Does not exist

trusty Does not exist
(trusty was ignored [Ubuntu touch end-of-life])
upstream Needs triage

xenial Ignored
(Ubuntu touch end-of-life)
yakkety Ignored
(reached end-of-life)
zesty Ignored
(reached end-of-life)