关键漏洞信息 漏洞概述 Title: Security: pdfium heap buffer overflow in cfx_dibbase.cpp CVE: 2021-37984 漏洞细节 Type: Heap buffer overflow in cfx_dibbase.cpp. Description: Memcpy source offset miscalculation leads to heap buffer overflow. Specifics: - value can cause an invalid memcopy source offset. - Adjusting in PDF can control the offset size. 技术详情 Location: cfx_dibbase.cpp:644 Trigger: Modifying size in PDF file. Example: - -> offset - -> offset 版本与案例 Affected Version: nightly build Reproduction PDF: 状态和优先级 Status: Fixed Priority: P1 Severity: S1 报告与修复 Reporter: ch...@gmail.com Assignee: ts...@chromium.org Fixed Date: Post-Sep 28, 2021