CVE-2014-3189: High severity google chrome (trace event) vulnerability
The chromepdf::CopyImage function in pdf/drawutils.cc in the PDFium component in Google Chrome before 38.0.2125.101 does not properly validate image-data dimensions, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via unknown vectors.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3189?
CVE-2014-3189 is classified as having a high severity due to its potential for causing a denial of service.
How do I fix CVE-2014-3189?
To fix CVE-2014-3189, update Google Chrome to version 38.0.2125.101 or later.
What software is affected by CVE-2014-3189?
CVE-2014-3189 affects various versions of Google Chrome prior to 38.0.2125.101 and specific Red Hat Enterprise Linux versions.
What type of vulnerability is CVE-2014-3189?
CVE-2014-3189 is a vulnerability in the PDFium component that involves improper validation of image-data dimensions.
Can CVE-2014-3189 lead to data leakage?
While CVE-2014-3189 primarily poses a denial of service risk, it may also have unspecified impacts that could lead to data exposure.