Candidate: CVE-2016-1685 PublicDate: 2016-06-05 23:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1685 http://googlechromereleases.blogspot.com/2016/05/stable-channel-update_25.html Description: core/fxge/ge/fx_ge_text.cpp in PDFium, as used in Google Chrome before 51.0.2704.63, miscalculates certain index values, which allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted PDF document. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Ke Liu Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H [6.5 MEDIUM] Patches_chromium-browser: upstream_chromium-browser: released (51.0.2704.63-1) precise_chromium-browser: ignored trusty_chromium-browser: released (51.0.2704.79-0ubuntu0.14.04.1.1121) trusty/esm_chromium-browser: DNE (trusty was released [51.0.2704.79-0ubuntu0.14.04.1.1121]) vivid/ubuntu-core_chromium-browser: DNE vivid/stable-phone-overlay_chromium-browser: DNE wily_chromium-browser: ignored (reached end-of-life) xenial_chromium-browser: released (51.0.2704.79-0ubuntu0.16.04.1.1242) devel_chromium-browser: released (51.0.2704.79-0ubuntu2~cm1) Patches_oxide-qt: upstream_oxide-qt: not-affected precise_oxide-qt: DNE trusty_oxide-qt: not-affected trusty/esm_oxide-qt: DNE (trusty was not-affected) vivid/ubuntu-core_oxide-qt: DNE vivid/stable-phone-overlay_oxide-qt: not-affected wily_oxide-qt: not-affected xenial_oxide-qt: not-affected esm-infra/xenial_oxide-qt: not-affected devel_oxide-qt: not-affected