PT-2018-3228 · Google+4 · Google Chrome+5

Zhou Aiting

·

Published

2018-05-10

·

Updated

2024-06-15

·

CVE-2018-6120

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 66.0.3359.170 Opera versions prior to 66.0.3359.170
Description The issue is related to an integer overflow in PDFium, a PDF content handler in Google Chrome and Opera, which could lead to a heap out-of-bounds write. This allows a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file.
Recommendations For Google Chrome versions prior to 66.0.3359.170, update to version 66.0.3359.170 or later. For Opera versions prior to 66.0.3359.170, update to a version that includes the fix for this issue, as the specific version is not provided. As a temporary workaround, consider avoiding the use of PDF files from untrusted sources until the issue is resolved.

Exploit

Fix

Memory Corruption

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-1959
BDU:2019-04389
CVE-2018-6120
DSA-4237-1
MGASA-2018-0268
OPENSUSE-SU-2018:1175-1
OPENSUSE-SU-2018:1437-1
OPENSUSE-SU-2018_1275-1
OPENSUSE-SU-2024:10681-1
OPENSUSE-SU-2024:12948-1
RHSA-2018:1446
RHSA-2018_1446

Affected Products

Alt Linux
Google Chrome
Opera
Pdfium
Red Hat
Suse