PT-2015-1673 · Google+4 · Google Chrome+5
Published
2015-07-21
·
Updated
2024-06-15
·
CVE-2015-1271
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Google Chrome versions prior to 44.0.2403.89
Description
The issue is caused by a heap-based buffer overflow in the PDFium component due to improper handling of out-of-memory conditions. This can be exploited by remote attackers using a specially crafted PDF document, potentially leading to a denial of service or other unspecified impacts.
Recommendations
For versions prior to 44.0.2403.89, update to version 44.0.2403.89 or later to resolve the issue. As a temporary workaround, consider restricting the use of PDF documents from untrusted sources to minimize the risk of exploitation.
Exploit
Fix
DoS
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Google Chrome
Opera
Pdfium
Red Hat
Suse