PT-2016-2153 · Google+4 · Google Chrome+5

Ke Liu

·

Published

2016-05-25

·

Updated

2024-06-15

·

CVE-2016-1685

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 51.0.2704.63 PDFium (affected versions not specified)
Description The issue is related to the incorrect handling of certain index values in the core/fxge/ge/fx ge text.cpp component of PDFium, used in Google Chrome. This can be exploited by a remote attacker to cause a denial of service, specifically an out-of-bounds read, by using a specially crafted PDF document.
Recommendations For Google Chrome versions prior to 51.0.2704.63, update to version 51.0.2704.63 or later to resolve the issue. As a temporary workaround, consider avoiding the use of PDF documents from untrusted sources until the update is applied. Restrict access to the core/fxge/ge/fx ge text.cpp component of PDFium to minimize the risk of exploitation.

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2016-2194
BDU:2016-01506
CVE-2016-1685
DSA-3590-1
MGASA-2016-0214
OPENSUSE-SU-2016_1430-1
OPENSUSE-SU-2016_1496-1
OPENSUSE-SU-2024:10171-1
OPENSUSE-SU-2024:12948-1
RHSA-2016:1190
RHSA-2016_1190

Affected Products

Alt Linux
Google Chrome
Opera
Pdfium
Red Hat
Suse