First published: Mon Apr 24 2017(Updated: )
A use after free in ANGLE in Google Chrome prior to 57.0.2987.98 for Windows allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
Credit: cve-coordination@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
Firefox | <53.0.2 | 53.0.2 |
Firefox ESR | <52.1.1 | 52.1.1 |
Google Chrome | <=57.0.2987.75 | |
Microsoft Windows Operating System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-5031 is classified as a high severity vulnerability due to its potential to allow remote attackers to execute arbitrary code.
To fix CVE-2017-5031, upgrade Google Chrome to version 57.0.2987.98 or later.
CVE-2017-5031 affects Google Chrome versions prior to 57.0.2987.98.
CVE-2017-5031 can be exploited through a crafted HTML page that triggers a use after free condition.
CVE-2017-5031 does not affect Firefox versions after 53.0.2, as the vulnerability has been fixed in subsequent releases.