CVE-2016-5211: Use After Free
Published Jan 19, 2017
·Updated
A use after free in PDFium in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
Affected Software
1 affected component
Google Chrome<=54.0.2840.99
Event History
Jan 19, 2017
CVE Published
via MITRE·05:43 AM
Data Sourced
via MITRE·05:43 AM
DescriptionWeakness
Data Sourced
via NVD·05:59 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-5211?
CVE-2016-5211 has been assigned a high severity rating due to the potential for remote attackers to exploit heap corruption.
2
How do I fix CVE-2016-5211?
To mitigate CVE-2016-5211, users should upgrade to Google Chrome version 55.0.2883.75 or later.
3
What effects does CVE-2016-5211 have on systems?
CVE-2016-5211 can lead to heap corruption which may allow an attacker to execute arbitrary code or crash the browser.
4
Which versions of Google Chrome are affected by CVE-2016-5211?
CVE-2016-5211 affects Google Chrome versions prior to 55.0.2883.75 for desktop and 55.0.2883.84 for Android.
5
Who is the vendor for the software affected by CVE-2016-5211?
The vendor for the affected software is Google, specifically the Google Chrome web browser.