Stack Overflow Vulnerability in Google Chrome's PDFium Component
CVE-2017-5095

8.8HIGH

Key Information:

Vendor
Google
Vendor
CVE Published:
27 October 2017

Summary

A stack overflow vulnerability exists in the PDFium component of Google Chrome that can be exploited through specially crafted PDF files. When an affected version of the browser processes a malicious PDF, it may lead to stack corruption, potentially allowing remote attackers to execute arbitrary code. Users are urged to update their browsers to the latest version to mitigate this risk and protect their systems.

Affected Version(s)

Google Chrome prior to 60.0.3112.78 for Linux, Windows and Mac Google Chrome prior to 60.0.3112.78 for Linux, Windows and Mac

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.