First published: Tue Apr 25 2017(Updated: )
An integer overflow in FFmpeg in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android allowed a remote attacker to perform an out of bounds memory write via a crafted video file, related to ChunkDemuxer.
Credit: cve-coordination@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Chrome | <=57.0.2987.75 | |
macOS | ||
Linux Kernel | ||
Microsoft Windows Operating System | ||
Google Chrome | <=57.0.2987.100 | |
Android |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-5049 has been classified as a high severity vulnerability due to its potential to allow remote code execution.
To fix CVE-2017-5049, users should update Google Chrome to version 57.0.2987.98 or later.
CVE-2017-5049 can allow an attacker to write to memory out of bounds, potentially leading to crashes or code execution.
CVE-2017-5049 affects Google Chrome versions prior to 57.0.2987.98.
CVE-2017-5049 is related to an integer overflow in the FFmpeg component of Google Chrome.