Integer Overflow Vulnerability in PDFium Affecting Google Chrome
CVE-2016-5223

6.5MEDIUM

Summary

An integer overflow vulnerability exists in the PDFium component of Google Chrome, present in versions prior to 55.0.2883.75 for Mac, Windows, and Linux, as well as 55.0.2883.84 for Android. This flaw enables remote attackers to manipulate crafted PDF files, potentially leading to heap corruption or denial of service conditions, affecting the security and integrity of the Chrome browser.

Affected Version(s)

Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.