CVE-2018-17469: Buffer Overflow
A heap buffer overflow flaw was found in the PDFium component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=880675
External References:
https://chromereleases.googleblog.com/2018/10/stable-channel-update-for-desktop.html
Other sources
Incorrect handling of PDF filter chains in PDFium in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to perform an out of bounds memory read via a crafted PDF file.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2018-17469.
What is the severity of CVE-2018-17469?
The severity of CVE-2018-17469 is high with a severity value of 8.8.
Which software is affected by CVE-2018-17469?
The affected software includes Google Chrome versions prior to 70.0.3538.67 and Chromium Browser versions prior to 70.0.3538.67 on Debian and Redhat Linux systems.
How does CVE-2018-17469 impact the affected software?
CVE-2018-17469 allows a remote attacker to perform an out of bounds memory read via a crafted PDF file in Google Chrome and Chromium Browser.
How can CVE-2018-17469 be fixed?
To fix CVE-2018-17469, update Google Chrome or Chromium Browser to version 70.0.3538.67 or later.