VulnerabilityModified
CVE-2017-5014
Heap buffer overflow during image processing in Skia in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
MEDIUM 6.3EPSS 1.36%
Does this matter?
Lower severity and a low EPSS score (1.36%). Track it; it rarely justifies an emergency change on its own.
Description
Heap buffer overflow during image processing in Skia in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
- CVSS 3.0
- 6.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
- EPSS
- 1.36% probability · 70th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- google/chrome
- Source
- chrome-cve-admin@google.com
References
- http://rhn.redhat.com/errata/RHSA-2017-0206.html
- http://www.debian.org/security/2017/dsa-3776
- http://www.securityfocus.com/bid/95792
- http://www.securitytracker.com/id/1037718
- https://chromereleases.googleblog.com/2017/01/stable-channel-update-for-desktop.html
- https://crbug.com/675332
- https://security.gentoo.org/glsa/201701-66
- http://rhn.redhat.com/errata/RHSA-2017-0206.html
- http://www.debian.org/security/2017/dsa-3776
- http://www.securityfocus.com/bid/95792
- http://www.securitytracker.com/id/1037718
- https://chromereleases.googleblog.com/2017/01/stable-channel-update-for-desktop.html
- https://crbug.com/675332
- https://security.gentoo.org/glsa/201701-66
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.