Unrated severityNVD Advisory· Published Jan 9, 2019· Updated Aug 5, 2024
CVE-2018-6120
CVE-2018-6120
Description
An integer overflow that could lead to an attacker-controlled heap out-of-bounds write in PDFium in Google Chrome prior to 66.0.3359.170 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file.
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- access.redhat.com/errata/RHSA-2018:1446mitrevendor-advisoryx_refsource_REDHAT
- security.gentoo.org/glsa/201805-06mitrevendor-advisoryx_refsource_GENTOO
- www.debian.org/security/2018/dsa-4237mitrevendor-advisoryx_refsource_DEBIAN
- www.securityfocus.com/bid/104143mitrevdb-entryx_refsource_BID
- chromereleases.googleblog.com/2018/05/stable-channel-update-for-desktop.htmlmitrex_refsource_CONFIRM
- crbug.com/833721mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.