CVE-2016-1681: Buffer Overflow
A heap overflow flaw was found in the PDFium component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=613160
External References:
http://googlechromereleases.blogspot.com/2016/05/stable-channel-update25.html
Other sources
Heap-based buffer overflow in the opjj2kreadSPCodSPCoc function in j2k.c in OpenJPEG, as used in PDFium in Google Chrome before 51.0.2704.63, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted PDF document.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1681?
CVE-2016-1681 has a high severity rating due to its potential to cause denial of service and impact from heap-based buffer overflow.
How do I fix CVE-2016-1681?
To fix CVE-2016-1681, upgrade to Chrome version 51.0.2704.63 or later.
What versions of Chrome are affected by CVE-2016-1681?
CVE-2016-1681 affects Google Chrome versions prior to 51.0.2704.63.
Which operating systems are impacted by CVE-2016-1681?
CVE-2016-1681 affects various operating systems including older versions of Debian, OpenSUSE, and Red Hat Enterprise Linux.
What type of attack could exploit CVE-2016-1681?
An attacker could exploit CVE-2016-1681 through a crafted PDF document to trigger a heap-based buffer overflow.