CVE-2017-5037Integer Overflow or Wraparound in Google Chrome

Severity
7.8HIGHNVD
OSV8.8
EPSS
0.3%
top 48.63%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 24
Latest updateApr 30

Description

An integer overflow in FFmpeg in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android allowed a remote attacker to perform an out of bounds memory write via a crafted video file, related to ChunkDemuxer.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages4 packages

Also affects: Debian Linux 8.0, 9.0

🔴Vulnerability Details

3
GHSA
GHSA-x9m7-4vf7-7448: An integer overflow in FFmpeg in Google Chrome prior to 572022-04-30
OSV
oxide-qt vulnerabilities2017-03-29
OSV
CVE-2017-5037: An integer overflow in FFmpeg in Google Chrome prior to 572017-03-10

📋Vendor Advisories

2
Ubuntu
Oxide vulnerabilities2017-03-29
Red Hat
chromium-browser: multiple out of bounds writes in chunkdemuxer2017-03-09

💬Community

2
Bugzilla
chromium: various flaws [fedora-all]2017-03-10
Bugzilla
CVE-2017-5037 CVE-2017-5047 CVE-2017-5048 CVE-2017-5049 CVE-2017-5050 CVE-2017-5051 chromium-browser: multiple out of bounds writes in chunkdemuxer2017-03-10