First published: Wed Oct 08 2014(Updated: )
The chrome_pdf::CopyImage function in pdf/draw_utils.cc in the PDFium component in Google Chrome before 38.0.2125.101 does not properly validate image-data dimensions, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via unknown vectors.
Credit: cve-coordination@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Chrome (Trace Event) | <=38.0.2125.7 | |
Red Hat Enterprise Linux Desktop | =6.0 | |
Red Hat Enterprise Linux Server Supplementary | =6.0 | |
Red Hat Enterprise Linux Server Supplementary EUS | =6.6.z | |
Red Hat Enterprise Linux Workstation Supplementary | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-3189 is classified as having a high severity due to its potential for causing a denial of service.
To fix CVE-2014-3189, update Google Chrome to version 38.0.2125.101 or later.
CVE-2014-3189 affects various versions of Google Chrome prior to 38.0.2125.101 and specific Red Hat Enterprise Linux versions.
CVE-2014-3189 is a vulnerability in the PDFium component that involves improper validation of image-data dimensions.
While CVE-2014-3189 primarily poses a denial of service risk, it may also have unspecified impacts that could lead to data exposure.