Integer Overflow Vulnerability in Google Chrome Affecting Multiple Platforms
CVE-2017-5051
8.8HIGH
Key Information:
- Vendor
- Vendor
- CVE Published:
- 25 April 2017
Summary
An integer overflow vulnerability exists in the FFmpeg library within Google Chrome. Versions prior to 57.0.2987.98 for desktop platforms (Mac, Windows, Linux) and 57.0.2987.108 for Android are affected. This flaw allows remote attackers to exploit crafted video files, leading to out of bounds memory write conditions. Such situations may allow for arbitrary code execution or application crashes, through careful manipulation of video playback functionality related to ChunkDemuxer.
Affected Version(s)
Google Chrome prior to 57.0.2987.98 for Mac, Windows and Linux, and 57.0.2987.108 for Android Google Chrome prior to 57.0.2987.98 for Mac, Windows and Linux, and 57.0.2987.108 for Android
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved