CVE-2019-5795: Integer overflow in PDFium
An integer overflow flaw was found in the PDFium component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=919643
External References:
https://chromereleases.googleblog.com/2019/03/stable-channel-update-for-desktop12.html
Other sources
Integer overflow in PDFium in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially perform out of bounds memory access via a crafted PDF file.
— MITRE
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2019-5795?
CVE-2019-5795 is classified as a high-severity vulnerability due to the potential for out of bounds memory access.
How do I fix CVE-2019-5795?
To fix CVE-2019-5795, upgrade to Chromium or Chrome version 73.0.3683.75 or later.
What systems are affected by CVE-2019-5795?
CVE-2019-5795 affects Google Chrome and Chromium browsers prior to version 73.0.3683.75.
What type of attack does CVE-2019-5795 facilitate?
CVE-2019-5795 allows a remote attacker to potentially exploit an integer overflow in PDFium via a crafted PDF file.
Can CVE-2019-5795 lead to data loss?
Exploitation of CVE-2019-5795 could lead to out of bounds memory access, which may result in data loss or corruption.