First published: Mon Apr 24 2017(Updated: )
Chrome Apps in Google Chrome prior to 57.0.2987.98 for Linux, Windows, and Mac had a use after free bug in GuestView, which allowed a remote attacker to perform an out of bounds memory read via a crafted Chrome extension.
Credit: cve-coordination@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Chrome | <=57.0.2987.75 | |
Apple iOS and macOS | ||
Linux Kernel | ||
Microsoft Windows | ||
Debian GNU/Linux | =8.0 | |
Debian GNU/Linux | =9.0 | |
redhat enterprise Linux desktop | =6.0 | |
redhat enterprise Linux server | =6.0 | |
redhat enterprise Linux workstation | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-5038 has a severity rating of medium, as it allows remote attackers to exploit a use after free vulnerability in Chrome apps.
To fix CVE-2017-5038, ensure that you update Google Chrome to version 57.0.2987.98 or later.
CVE-2017-5038 affects Google Chrome versions prior to 57.0.2987.98.
CVE-2017-5038 affects Chrome Apps in Google Chrome on Linux, Windows, and Mac.
CVE-2017-5038 is a use after free vulnerability that can lead to out of bounds memory reads.