First published: Mon Apr 24 2017(Updated: )
PDFium in Google Chrome prior to 57.0.2987.98 for Windows could be made to increment off the end of a buffer, which allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
Credit: cve-coordination@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Chrome | <=57.0.2987.75 | |
Microsoft Windows Operating System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-5032 is classified as a critical vulnerability due to its potential for heap corruption and remote exploitation.
To fix CVE-2017-5032, update Google Chrome to version 57.0.2987.98 or later.
Attackers could exploit CVE-2017-5032 by crafting a malicious PDF file that leads to heap corruption.
CVE-2017-5032 affects Google Chrome versions before 57.0.2987.98.
CVE-2017-5032 specifically targets Google Chrome for Windows.