CVE-2017-5127 describes a use-after-free vulnerability in PDFium within Google Chrome prior to version 62.0.3202.62, affecting Google Chrome and Debian Linux distributions. This flaw allows a remote attacker to potentially exploit heap corruption by enticing a user to open a specially crafted PDF file. With a CVSS score of 8.8 (High), it presents a significant risk, enabling high impact to confidentiality, integrity, and availability through a low-complexity attack requiring user interaction. While there are no known public exploits (Metasploit, Nuclei, ExploitDB) and it's not listed in CISA's KEV catalog, the vulnerability has garnered notable community discussion and media coverage, indicating awareness despite the lack of confirmed active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 62.0.3202.62CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.