CVE-2017-5050: Integer Overflow
An integer overflow in FFmpeg in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android allowed a remote attacker to perform an out of bounds memory write via a crafted video file, related to ChunkDemuxer.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-5050?
CVE-2017-5050 has a high severity rating due to the potential for remote code execution from a crafted video file.
How do I fix CVE-2017-5050?
To fix CVE-2017-5050, update Google Chrome to version 57.0.2987.98 or later.
What types of systems are affected by CVE-2017-5050?
CVE-2017-5050 affects Google Chrome versions prior to 57.0.2987.98 on Mac, Windows, and Linux.
What can an attacker achieve by exploiting CVE-2017-5050?
An attacker can perform an out of bounds memory write, potentially leading to arbitrary code execution.
Is CVE-2017-5050 a zero-day vulnerability?
CVE-2017-5050 was disclosed publicly but was not classified as a zero-day since it received a patch shortly after discovery.