CVE-2016-1684: Integer Overflow
An integer overflow flaw was found in the libxslt component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=583171
External References:
http://googlechromereleases.blogspot.com/2016/05/stable-channel-update25.html
Other sources
numbers.c in libxslt before 1.1.29, as used in Google Chrome before 51.0.2704.63, mishandles the i format token for xsl:number data, which allows remote attackers to cause a denial of service (integer overflow or resource consumption) or possibly have unspecified other impact via a crafted document.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1684?
CVE-2016-1684 has a moderate severity rating due to its potential for causing denial of service through resource consumption.
How do I fix CVE-2016-1684?
To fix CVE-2016-1684, update Google Chrome to version 51.0.2704.63 or later and ensure libxslt is updated beyond version 1.1.28.
What systems are affected by CVE-2016-1684?
CVE-2016-1684 affects Google Chrome versions up to 50.0.2661.102 and libxslt versions up to 1.1.28.
What type of attack can exploit CVE-2016-1684?
CVE-2016-1684 can be exploited by attackers to cause a denial of service through integer overflow or resource consumption.
Is CVE-2016-1684 being actively exploited?
There is no public indication that CVE-2016-1684 is being actively exploited in the wild, but it still poses a potential risk.