Candidate: CVE-2016-5210 PublicDate: 2017-01-19 05:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5210 https://googlechromereleases.blogspot.com/2016/12/stable-channel-update-for-desktop.html Description: Heap buffer overflow during TIFF image parsing in PDFium in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Ke Liu Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H [8.8 HIGH] Patches_chromium-browser: upstream_chromium-browser: released (55.0.2883.75) precise_chromium-browser: ignored trusty_chromium-browser: released (58.0.3029.81-0ubuntu0.14.04.1172) trusty/esm_chromium-browser: DNE (trusty was released [58.0.3029.81-0ubuntu0.14.04.1172]) vivid/ubuntu-core_chromium-browser: DNE vivid/stable-phone-overlay_chromium-browser: DNE xenial_chromium-browser: released (55.0.2883.87-0ubuntu0.16.04.1263) yakkety_chromium-browser: released (55.0.2883.87-0ubuntu0.16.10.1328) zesty_chromium-browser: released (55.0.2883.87-0ubuntu1) devel_chromium-browser: released (55.0.2883.87-0ubuntu1) Patches_oxide-qt: upstream_oxide-qt: not-affected precise_oxide-qt: DNE trusty_oxide-qt: not-affected trusty/esm_oxide-qt: DNE (trusty was not-affected) vivid/ubuntu-core_oxide-qt: DNE vivid/stable-phone-overlay_oxide-qt: not-affected xenial_oxide-qt: not-affected esm-infra/xenial_oxide-qt: not-affected yakkety_oxide-qt: not-affected zesty_oxide-qt: not-affected devel_oxide-qt: not-affected