Junglewise Threat Intelligence

CVE-2016-5223: Google Chrome integer overflow in PDFium

CVE-2016-5223 · Severity: medium · CVSS 6.5 · Published 2017-01-19

Technologies: Google Chromium, Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A vulnerability was identified in its PDF viewing component, PDFium, which could allow a malicious website to crash the browser or potentially corrupt its memory. This occurs when a user is tricked into opening a specially crafted PDF file, which could lead to a temporary service disruption or further security compromises.

Technical details

An integer overflow vulnerability exists in PDFium, the PDF rendering engine used in Google Chrome and Chromium-based browsers. The flaw is triggered when the engine processes a malformed PDF file containing specific crafted values that lead to an arithmetic overflow. A remote attacker can exploit this by hosting a malicious PDF on a website or sending it via email, requiring the user to open the file. Successful exploitation can result in heap corruption or a Denial of Service (DoS) crash. The issue was addressed in Chrome version 55.0.2883.75 for desktop platforms and 55.0.2883.84 for Android.

Affected products

  • Google Chrome Prior to 55.0.2883.75 (Desktop); Prior to 55.0.2883.84 (Android)
  • Google Chromium Prior to 55.0.2883.75

Timeline

  • 2016-12-01: advisory: Google released Chrome 55.0.2883.75 with security fixes
  • 2016-12-05: advisory: Gentoo released security advisory GLSA 201612-11
  • 2016-12-07: patched: Red Hat released RHSA-2016:2919 for chromium-browser
  • 2017-01-19: disclosed: NVD publication date

References

Related threats