GHSA-pjpr-2qqp-gprf
Dashboard / Vulnerabilities / GHSA-pjpr-2qqp-gprf
Summary: ChakraCore information disclosure vulnerability
Details: An information disclosure vulnerability exists in Microsoft Edge when the Chakra scripting engine does not properly handle objects in memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user's system, a.k.a. "Scripting Engine Information Disclosure Vulnerability."
References: https://nvd.nist.gov/vuln/detail/CVE-2017-0208, https://github.com/chakra-core/ChakraCore/pull/2834, https://github.com/chakra-core/ChakraCore/commit/54d6d085987e2c399863940179db67b594d7f0a3, https://github.com/chakra-core/ChakraCore, https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0208, https://web.archive.org/web/20210124023848/http://www.securityfocus.com/bid/97460, https://web.archive.org/web/20211201121401/http://www.securitytracker.com/id/1038234
Affected packages
Package
Name: Microsoft.ChakraCore
Purl: pkg:nuget/Microsoft.ChakraCore
Affected ranges
Type: ECOSYSTEM
Events:
