Integer Overflow in FFmpeg Affects Google Chrome for Multiple Platforms
CVE-2017-5037
7.8HIGH
Key Information:
- Vendor
- Vendor
- CVE Published:
- 24 April 2017
Summary
A vulnerability exists in FFmpeg within Google Chrome that can lead to an integer overflow. This flaw allows remote attackers to exploit crafted video files for an out of bounds memory write. It particularly relates to the ChunkDemuxer component and affects various versions of Google Chrome across multiple platforms, including Mac, Windows, Linux, and Android. Users are encouraged to update their browsers to mitigate risks associated with this security issue.
Affected Version(s)
Google Chrome prior to 57.0.2987.98 for Mac, Windows and Linux, and 57.0.2987.108 for Android Google Chrome prior to 57.0.2987.98 for Mac, Windows and Linux, and 57.0.2987.108 for Android
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved