CVE-2017-5119: Debian Linux

Medium severity, CVSS 4.3. EPSS: 1.8% chance of exploitation in the next 30 days.

Use of an uninitialized value in Skia in Google Chrome prior to 61.0.3163.79 for Mac, Windows, and Linux, and 61.0.3163.81 for Android, allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

Affected products

  • Debian Debian Linux: version 9.0 only
  • Google Chrome: before 61.0.3163.100 (fixed in 61.0.3163.100)

Published 2017-10-27. Last modified 2026-06-17.