CVE-2018-17481: Use After Free
An use after frees flaw was found in the PDFium component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=901654
External References:
https://chromereleases.googleblog.com/2018/12/stable-channel-update-for-desktop.html
Other sources
Incorrect object lifecycle handling in PDFium in Google Chrome prior to 71.0.3578.98 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-17481?
CVE-2018-17481 is a vulnerability in PDFium in Google Chrome prior to version 71.0.3578.98 that allows a remote attacker to potentially exploit heap corruption via a crafted PDF file.
What is the severity of CVE-2018-17481?
CVE-2018-17481 has a severity score of 8.8 and is considered high.
Which software versions are affected by CVE-2018-17481?
Google Chrome prior to version 71.0.3578.98, Redhat Linux Desktop 6.0, Redhat Linux Server 6.0, Redhat Linux Workstation 6.0, and Debian Debian Linux 9.0 are affected by CVE-2018-17481.
How can an attacker exploit CVE-2018-17481?
An attacker can potentially exploit CVE-2018-17481 by using a crafted PDF file to trigger heap corruption.
How can I fix CVE-2018-17481?
To fix CVE-2018-17481, update Google Chrome to version 71.0.3578.98 or later, or apply the appropriate security patches from Redhat or Debian.