CVE-2012-2856: Buffer Overflow
Published Aug 6, 2012
·Updated
The PDF functionality in Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows and Chrome Frame, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger out-of-bounds write operations.
Affected Software
31 affected components
Google Chrome<=21.0.1180.56
Google Chrome=21.0.1180.0
Google Chrome=21.0.1180.1
Google Chrome=21.0.1180.2
Google Chrome=21.0.1180.31
Google Chrome=21.0.1180.32
Google Chrome=21.0.1180.33
Google Chrome=21.0.1180.34
Google Chrome=21.0.1180.35
Google Chrome=21.0.1180.36
Google Chrome=21.0.1180.37
Google Chrome=21.0.1180.38
Google Chrome=21.0.1180.39
Google Chrome=21.0.1180.41
Google Chrome=21.0.1180.46
Google Chrome=21.0.1180.47
Google Chrome=21.0.1180.48
Google Chrome=21.0.1180.49
Google Chrome=21.0.1180.50
Google Chrome=21.0.1180.51
Google Chrome=21.0.1180.52
Google Chrome=21.0.1180.53
Google Chrome=21.0.1180.54
Google Chrome=21.0.1180.55
Apple iOS and macOS
Linux Linux kernel
Google Chrome<=21.0.1180.59
Google Chrome=21.0.1180.56
Google Chrome=21.0.1180.57
Google Frame
Microsoft Windows
Event History
Aug 6, 2012
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-2856?
CVE-2012-2856 has a medium severity rating as it can lead to denial of service or other unspecified impacts.
2
How do I fix CVE-2012-2856?
To fix CVE-2012-2856, users should update Google Chrome to version 21.0.1180.57 or later.
3
Which versions of Google Chrome are affected by CVE-2012-2856?
CVE-2012-2856 affects Google Chrome versions prior to 21.0.1180.57.
4
Can CVE-2012-2856 be exploited remotely?
Yes, CVE-2012-2856 can be exploited remotely by attacking the PDF functionality in affected versions of Google Chrome.
5
Is CVE-2012-2856 specific to any operating system?
CVE-2012-2856 affects Google Chrome on Mac OS X, Linux, and Windows platforms.