Integer Overflow Vulnerability in PDFium Affecting Google Chrome
CVE-2016-5223
6.5MEDIUM
Key Information:
- Vendor
- Vendor
- CVE Published:
- 19 January 2017
Summary
An integer overflow vulnerability exists in the PDFium component of Google Chrome, present in versions prior to 55.0.2883.75 for Mac, Windows, and Linux, as well as 55.0.2883.84 for Android. This flaw enables remote attackers to manipulate crafted PDF files, potentially leading to heap corruption or denial of service conditions, affecting the security and integrity of the Chrome browser.
Affected Version(s)
Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved