CVE-2020-6458:Out of bounds read and write vulnerability in PDFium component of Google Chrome

splash
Back

Description Preview

CVE-2020-6458 is a vulnerability in the PDFium component of Google Chrome versions prior to 81.0.4044.122. This vulnerability involves both out-of-bounds read (CWE-125) and out-of-bounds write (CWE-787) issues, which could allow a remote attacker to potentially exploit heap corruption via a specially crafted PDF file. When successfully exploited, this vulnerability could lead to arbitrary code execution within the browser context or potentially cause browser crashes.

Overview

This vulnerability affects the PDFium component, which is the PDF rendering engine used in Google Chrome. The issue stems from improper validation of input when processing certain PDF files, leading to both out-of-bounds read and write operations. An attacker could exploit this vulnerability by enticing a user to open a maliciously crafted PDF file in Chrome, which could trigger heap corruption. Successful exploitation could potentially lead to arbitrary code execution within the browser's security context, information disclosure, or denial of service through browser crashes. The vulnerability is particularly concerning as PDF viewing is a common activity in web browsers, making this a practical attack vector.

Remediation

Users should update to Google Chrome version 81.0.4044.122 or later, which contains the fix for this vulnerability. The update can be installed through Chrome's built-in update mechanism by:

  1. Opening Chrome and clicking on the three dots in the top-right corner
  2. Going to Help > About Google Chrome
  3. Allowing Chrome to automatically check for and install updates

System administrators in enterprise environments should ensure that Chrome browsers are updated to the patched version across all systems. Additionally, users should exercise caution when opening PDF files from untrusted sources, especially until the update is applied.

For Debian users, the vulnerability has been addressed in DSA-4714, and the appropriate security updates should be applied.

References

  1. Chrome Release Blog announcement: https://chromereleases.googleblog.com/2020/04/stable-channel-update-for-desktop_21.html
  2. Chrome Bug Tracker: https://crbug.com/1067270
  3. Debian Security Advisory DSA-4714: https://www.debian.org/security/2020/dsa-4714
  4. Talos Intelligence Vulnerability Report: https://www.talosintelligence.com/vulnerability_reports/TALOS-2020-1044
  5. Common Weakness Enumeration: CWE-125 (Out-of-bounds Read) and CWE-787 (Out-of-bounds Write)

Industry ExposureMost to least
This section illustrates the prevalence of a specific Common Vulnerabilities and Exposures (CVE) across various industries based on customer reports. The ranking displays industries from the most to least affected by this particular vulnerability, offering valuable insight into where this CVE has been most frequently observed. This information can help organizations within these sectors prioritize their security efforts, understand their relative risk exposure compared to their peers, and focus remediation strategies where they are most needed. By understanding the industry-specific impact, organizations can make more informed decisions regarding patching, resource allocation, and overall risk management related to this CVE.

  1. Health Care & Social Assistance
    Health Care & Social Assistance
  2. Manufacturing
    Manufacturing
  3. Educational Services
    Educational Services
  4. Public Administration
    Public Administration
  5. Transportation & Warehousing
    Transportation & Warehousing
  6. Retail Trade
    Retail Trade
  7. Other Services (except Public Administration)
    Other Services (except Public Administration)
  8. Arts, Entertainment & Recreation
    Arts, Entertainment & Recreation
  9. Finance and Insurance
    Finance and Insurance
  10. Professional, Scientific, & Technical Services
    Professional, Scientific, & Technical Services
  11. Utilities
    Utilities
  12. Information
    Information
  13. Management of Companies & Enterprises
    Management of Companies & Enterprises
  14. Construction
    Construction
  15. Mining
    Mining
  16. Real Estate Rental & Leasing
    Real Estate Rental & Leasing
  17. Accommodation & Food Services
    Accommodation & Food Services
  18. Agriculture, Forestry Fishing & Hunting
    Agriculture, Forestry Fishing & Hunting
  19. Wholesale Trade
    Wholesale Trade
  20. Administrative, Support, Waste Management & Remediation Services
    Administrative, Support, Waste Management & Remediation Services

Focus on What Matters

  1. See Everything.
  2. Identify True Risk.
  3. Proactively Mitigate Threats.

Let's talk!

background