CVE-2017-5049Integer Overflow or Wraparound in Google Chrome

Severity
8.8HIGHNVD
EPSS
0.3%
top 45.77%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 25
Latest updateMay 13

Description

An integer overflow in FFmpeg in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android allowed a remote attacker to perform an out of bounds memory write via a crafted video file, related to ChunkDemuxer.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages1 packages

NVDgoogle/chrome57.0.2987.75+1

🔴Vulnerability Details

2
GHSA
GHSA-33c5-fq57-8p37: An integer overflow in FFmpeg in Google Chrome prior to 572022-05-13
OSV
CVE-2017-5049: An integer overflow in FFmpeg in Google Chrome prior to 572017-04-25

📋Vendor Advisories

1
Red Hat
chromium-browser: multiple out of bounds writes in chunkdemuxer2017-03-09

💬Community

1
Bugzilla
CVE-2017-5037 CVE-2017-5047 CVE-2017-5048 CVE-2017-5049 CVE-2017-5050 CVE-2017-5051 chromium-browser: multiple out of bounds writes in chunkdemuxer2017-03-10