CVE-2017-5031: Use After Free
A use after free in ANGLE in Google Chrome prior to 57.0.2987.98 for Windows allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
Other sources
A use-after-free can occur during Buffer11 API calls within the ANGLE graphics library, used for WebGL content. This can lead to a potentially exploitable crash. Note: This issue is in libGLES, which is only in use on Windows. Other operating systems are not affected.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 53.0.2 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 52.1.1
Event History
Frequently Asked Questions
What is the severity of CVE-2017-5031?
CVE-2017-5031 is classified as a high severity vulnerability due to its potential to allow remote attackers to execute arbitrary code.
How do I fix CVE-2017-5031?
To fix CVE-2017-5031, upgrade Google Chrome to version 57.0.2987.98 or later.
Which versions of Google Chrome are affected by CVE-2017-5031?
CVE-2017-5031 affects Google Chrome versions prior to 57.0.2987.98.
What type of attack can exploit CVE-2017-5031?
CVE-2017-5031 can be exploited through a crafted HTML page that triggers a use after free condition.
Is CVE-2017-5031 present in Firefox?
CVE-2017-5031 does not affect Firefox versions after 53.0.2, as the vulnerability has been fixed in subsequent releases.