Executive brief
Google Chrome's PDF viewer, PDFium, contains a security flaw in how it processes TIFF images within PDF documents. An attacker could exploit this by tricking a user into opening a specially crafted PDF file, potentially leading to a browser crash or unauthorized access to data. This could impact the confidentiality and integrity of information handled within the browser session.
Technical details
A heap buffer overflow vulnerability (CWE-787) exists in the PDFium engine used by Google Chrome and Chromium-based browsers. The flaw is triggered during the parsing of TIFF images embedded within PDF files. A remote, unauthenticated attacker can exploit this by enticing a user to open a malicious PDF, leading to an out-of-bounds write on the heap. This memory corruption can result in a denial-of-service (browser crash) or potentially arbitrary code execution within the context of the browser's sandbox. The issue was addressed in Chrome version 55.0.2883.75 for desktop platforms and 55.0.2883.84 for Android.
Affected products
- Google Chrome Prior to 55.0.2883.75 (Mac, Windows, Linux); Prior to 55.0.2883.84 (Android)
- Google Chromium Prior to 55.0.2883.75
Timeline
- 2016-12-01: advisory: Google released Chrome 55.0.2883.75 to the stable channel
- 2016-12-05: advisory: Gentoo security advisory published
- 2016-12-07: patched: Red Hat released updated chromium-browser packages
- 2017-01-19: disclosed: NVD publication date