CVE-2019-13706: High severity google chrome (trace event) vulnerability
Published Nov 25, 2019
·Updated
Out of bounds memory access in PDFium in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
Affected Software
2 affected components
Google Chrome<78.0.3904.70
openSUSE Backports=15.0-sp1
Event History
Nov 25, 2019
CVE Published
via MITRE·02:22 PM
Data Sourced
via MITRE·02:22 PM
DescriptionWeakness
Frequently Asked Questions
1
What does an attacker need to exploit this issue?
An attacker needs to get a user to interact with a crafted PDF file. The CVSS vector indicates local attack vector, no privileges required, and user interaction required.
2
Which Chrome versions are affected?
Google Chrome versions prior to 78.0.3904.70 are affected according to the available data.
3
What is the likely impact of successful exploitation?
Successful exploitation could cause heap corruption through an out-of-bounds memory access in PDFium. The CVSS rating indicates potential high impact to confidentiality, integrity, and availability.