CVE-2016-1686: Buffer Overflow
An out-of-bounds read flaw was found in the PDFium component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=603518
External References:
http://googlechromereleases.blogspot.com/2016/05/stable-channel-update25.html
Other sources
The CPDFDIBSource::CreateDecoder function in core/fpdfapi/fpdfrender/fpdfrenderloadimage.cpp in PDFium, as used in Google Chrome before 51.0.2704.63, mishandles decoder-initialization failure, which allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted PDF document.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1686?
CVE-2016-1686 is classified as a denial of service vulnerability that can allow attackers to cause an out-of-bounds read.
How do I fix CVE-2016-1686?
To fix CVE-2016-1686, update Google Chrome to version 51.0.2704.63 or later, as this version addresses the vulnerability.
What versions of Google Chrome are affected by CVE-2016-1686?
CVE-2016-1686 affects Google Chrome versions prior to 51.0.2704.63.
Can CVE-2016-1686 be exploited by attackers?
Yes, CVE-2016-1686 can be exploited by remote attackers through specially crafted PDF documents.
Which operating systems are impacted by CVE-2016-1686?
CVE-2016-1686 impacts multiple operating systems including various versions of Debian, openSUSE, and Red Hat Enterprise Linux.