CVE-2017-5044: Buffer Overflow
Published Apr 24, 2017
·Updated
Heap buffer overflow in filter processing in Skia in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
Affected Software
17 affected components
Google Chrome<=57.0.2987.75
Apple macOS
Linux Linux kernel
Microsoft Windows
Google Chrome<=57.0.2987.100
Google Android
Debian Debian Linux=8.0
Debian Debian Linux=9.0
redhat Enterprise Linux Desktop=6.0
redhat Enterprise Linux Server=6.0
redhat Enterprise Linux Workstation=6.0
All of the following
Google Chrome<=57.0.2987.75
Any of the following
Apple macOS
Linux Linux kernel
Microsoft Windows
All of the following
Google Chrome<=57.0.2987.100
Google Android
Remediation
Patch Available
Event History
Apr 24, 2017
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
DescriptionWeakness
Data Sourced
via NVD·11:59 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-5044?
CVE-2017-5044 has a high severity rating due to the potential for remote code execution.
2
How do I fix CVE-2017-5044?
To fix CVE-2017-5044, upgrade Google Chrome to version 57.0.2987.98 or later.
3
Which versions of Google Chrome are affected by CVE-2017-5044?
CVE-2017-5044 affects Google Chrome versions prior to 57.0.2987.98 on Mac, Windows, and Linux.
4
Can CVE-2017-5044 be exploited through a normal web page?
Yes, CVE-2017-5044 can be exploited through a crafted HTML page.
5
Are there any specific operating systems affected by CVE-2017-5044?
Yes, CVE-2017-5044 primarily affects Google Chrome on Mac, Windows, and Linux systems.