Executive brief
A security vulnerability in the Google Chrome web browser could allow an attacker to compromise a user's computer if they view a specially crafted video file. The issue exists in the FFmpeg component, which handles media playback, and could lead to unauthorized data access or system crashes. Users are protected by updating to the latest version of the browser.
Technical details
An off-by-one error in FFmpeg, as used in Google Chrome, leads to an allocation of zero size, resulting in heap corruption. The vulnerability is triggered when the browser processes a maliciously crafted video file. A remote attacker can exploit this flaw by enticing a user to visit a website containing the malicious media content. Successful exploitation could allow for arbitrary code execution within the context of the browser process or a denial-of-service (DoS) condition. The issue was addressed in Chrome versions 54.0.2840.98 (Mac), 54.0.2840.99 (Windows), 54.0.2840.100 (Linux), and 55.0.2883.84 (Android).
Affected products
- Google Chrome < 54.0.2840.98 (Mac), < 54.0.2840.99 (Windows), < 54.0.2840.100 (Linux), < 55.0.2883.84 (Android)
- Google Chromium < 54.0.2840.100
Timeline
- 2016-11-09: patched: Chrome stable channel update released for desktop platforms.
- 2016-11-14: advisory: Red Hat security advisory RHSA-2016:2718 published.
- 2017-01-19: disclosed: NVD publication date.