CVE-2021-37984: Heap buffer overflow in PDFium
Heap buffer overflow in PDFium in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2021-37984?
CVE-2021-37984 is considered a critical vulnerability due to the potential for remote code execution through heap corruption.
How do I fix CVE-2021-37984?
To fix CVE-2021-37984, update Google Chrome to version 95.0.4638.54 or later, or update your Chromium package to the patched version in Debian.
Which versions of Chrome are affected by CVE-2021-37984?
Versions of Google Chrome prior to 95.0.4638.54 are affected by CVE-2021-37984.
Can CVE-2021-37984 be exploited remotely?
Yes, CVE-2021-37984 allows a remote attacker to exploit the vulnerability via a specially crafted HTML page.
Which software needs to be updated to patch CVE-2021-37984?
You need to update Google Chrome or the Chromium package in Debian to mitigate the risks associated with CVE-2021-37984.