CVE-2016-1685: Buffer Overflow
An out-of-bounds read flaw was found in the PDFium component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=601362
External References:
http://googlechromereleases.blogspot.com/2016/05/stable-channel-update25.html
Other sources
core/fxge/ge/fxgetext.cpp in PDFium, as used in Google Chrome before 51.0.2704.63, miscalculates certain index values, which allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted PDF document.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1685?
CVE-2016-1685 is classified as a denial of service vulnerability that can lead to application crashes.
How do I fix CVE-2016-1685?
To fix CVE-2016-1685, upgrade to Google Chrome version 51.0.2704.63 or later.
What software is affected by CVE-2016-1685?
CVE-2016-1685 affects Google Chrome versions before 51.0.2704.63 and various Linux distributions using outdated versions.
Can CVE-2016-1685 be exploited remotely?
Yes, CVE-2016-1685 can be exploited remotely via crafted PDF documents.
What are the potential consequences of CVE-2016-1685?
The potential consequences of CVE-2016-1685 include application instability and denial of service on vulnerable systems.