CVE-2016-5154: Buffer Overflow
Multiple heap-based buffer overflows in PDFium, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, allow remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted JBig2 image.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-5154?
CVE-2016-5154 is considered a high-severity vulnerability due to the potential for remote denial of service attacks.
How do I fix CVE-2016-5154?
To mitigate CVE-2016-5154, update Google Chrome to version 53.0.2785.89 or later, or update openSUSE to a version that patches this vulnerability.
What types of attacks are possible with CVE-2016-5154?
CVE-2016-5154 allows attackers to cause denial of service or possibly gain further unspecified impacts through crafted JBig2 images.
Which software is affected by CVE-2016-5154?
CVE-2016-5154 affects Google Chrome versions prior to 53.0.2785.89 on Windows and OS X, and prior to 53.0.2785.92 on Linux, as well as openSUSE Leap 42.1.
Is there any workaround for CVE-2016-5154?
There are no specific workarounds for CVE-2016-5154 other than applying the available software updates.