PT-2015-2395 · Opera+3 · Opera+4

Tom Sepez

·

Published

2015-10-15

·

Updated

2024-06-15

·

CVE-2015-6756

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 46.0.2490.71 PDFium (affected versions not specified) Opera (affected versions not specified)
Description The issue is related to a use-after-free vulnerability in the CPDFSDK PageView implementation in PDFium, which can be exploited by remote attackers using a specially crafted PDF file. This can lead to a denial of service due to heap memory corruption or possibly have other unspecified impacts. The vulnerability is caused by the mishandling of a focused annotation in a PDF document.
Recommendations For Google Chrome versions prior to 46.0.2490.71, update to version 46.0.2490.71 or later to resolve the issue. For PDFium, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For Opera, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2015-1899
BDU:2015-11760
CVE-2015-6756
DSA-3376-1
MGASA-2015-0410
OPENSUSE-SU-2024:10171-1
OPENSUSE-SU-2024:12948-1
RHSA-2015:1912
RHSA-2015_1912

Affected Products

Alt Linux
Google Chrome
Opera
Pdfium
Red Hat