PT-2018-3228 · Google+4 · Google Chrome+5
Zhou Aiting
·
Publicado
2018-05-10
·
Atualizado
2024-06-15
·
CVE-2018-6120
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Google Chrome versions prior to 66.0.3359.170
Opera versions prior to 66.0.3359.170
Description
The issue is related to an integer overflow in PDFium, a PDF content handler in Google Chrome and Opera, which could lead to a heap out-of-bounds write. This allows a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file.
Recommendations
For Google Chrome versions prior to 66.0.3359.170, update to version 66.0.3359.170 or later.
For Opera versions prior to 66.0.3359.170, update to a version that includes the fix for this issue, as the specific version is not provided.
As a temporary workaround, consider avoiding the use of PDF files from untrusted sources until the issue is resolved.
Exploit
Correção
Memory Corruption
Integer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Alt Linux
Google Chrome
Opera
Pdfium
Red Hat
Suse