First published: Tue Jan 27 2015(Updated: )
Multiple off-by-one errors in fpdfapi/fpdf_font/font_int.h in PDFium, as used in Google Chrome before 40.0.2214.91, allow remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a crafted PDF document, related to an "intra-object-overflow" issue, a different vulnerability than CVE-2015-1205.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Google Chrome | <=40.0.2214.85 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-1359 has a medium severity rating and can lead to a denial of service or other impacts.
To fix CVE-2015-1359, update Google Chrome to version 40.0.2214.91 or later.
CVE-2015-1359 can be exploited by attackers using crafted PDF documents to trigger buffer overflows.
CVE-2015-1359 affects Google Chrome versions prior to 40.0.2214.91.
CVE-2015-1359 is related to intra-object overflow issues within the PDFium library.