Heap Buffer Overflow in Image Processing of Google Chrome
CVE-2017-5014
6.3MEDIUM
Key Information:
- Vendor
- Vendor
- CVE Published:
- 17 February 2017
Summary
This vulnerability involves a heap buffer overflow that occurs during image processing in the Skia graphics library within Google Chrome. Attackers can exploit this flaw by crafting a malicious HTML page that, when opened by a user, allows them to trigger an out of bounds memory read. This can potentially lead to information disclosure or execution of arbitrary code. Users are advised to update to the latest version of Google Chrome to mitigate risks associated with this vulnerability.
Affected Version(s)
Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android
References
CVSS V3.1
Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved