First published: Mon Apr 24 2017(Updated: )
A use after free in PDFium in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android allowed a remote attacker to have an unspecified impact via a crafted PDF file.
Credit: cve-coordination@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Chrome | <=57.0.2987.75 | |
macOS | ||
Linux Kernel | ||
Microsoft Windows Operating System | ||
Google Chrome | <=57.0.2987.100 | |
Android | ||
Debian Linux | =8.0 | |
Debian Linux | =9.0 | |
Red Hat Enterprise Linux Desktop | =6.0 | |
Red Hat Enterprise Linux Server | =6.0 | |
Red Hat Enterprise Linux Workstation | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-5036 is rated as a high severity vulnerability due to its potential to allow remote code execution via crafted PDF files.
To address CVE-2017-5036, update Google Chrome to the latest version beyond 57.0.2987.98.
CVE-2017-5036 affects Google Chrome on Mac, Windows, and Linux operating systems.
Yes, a remote attacker can exploit CVE-2017-5036 by delivering a crafted PDF file to the affected Chrome version.
CVE-2017-5036 specifically affects versions of Google Chrome up to and including 57.0.2987.98.