First published: Mon Apr 24 2017(Updated: )
An integer overflow in FFmpeg in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android allowed a remote attacker to perform an out of bounds memory write via a crafted video file, related to ChunkDemuxer.
Credit: cve-coordination@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Chrome | <=57.0.2987.75 | |
Apple macOS | ||
Linux Kernel | ||
Microsoft Windows | ||
Google Chrome | <=57.0.2987.100 | |
Google Android | ||
Debian Debian Linux | =8.0 | |
Debian Debian Linux | =9.0 | |
redhat enterprise Linux desktop | =6.0 | |
redhat enterprise Linux server | =6.0 | |
redhat enterprise Linux workstation | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-5037 has a severity rating classified as high due to its potential impact on system security.
To fix CVE-2017-5037, update Google Chrome to version 57.0.2987.98 or later.
Google Chrome versions prior to 57.0.2987.98 for Mac, Windows, and Linux are affected by CVE-2017-5037.
Yes, CVE-2017-5037 can affect Android devices running versions of Google Chrome prior to 57.0.2987.108.
No, the Linux Kernel is not vulnerable to CVE-2017-5037.