CVE-2014-3189Out-of-bounds Read in Google Chrome

Severity
7.5HIGHNVD
EPSS
0.7%
top 28.61%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 8
Latest updateMay 17

Description

The chrome_pdf::CopyImage function in pdf/draw_utils.cc in the PDFium component in Google Chrome before 38.0.2125.101 does not properly validate image-data dimensions, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via unknown vectors.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages3 packages

Also affects: Enterprise Linux 6.0, 6.6.z

🔴Vulnerability Details

3
GHSA
GHSA-x5x9-qv4j-r93j: The chrome_pdf::CopyImage function in pdf/draw_utils2022-05-17
CVEList
CVE-2014-3189: The chrome_pdf::CopyImage function in pdf/draw_utils2014-10-08
OSV
CVE-2014-3189: The chrome_pdf::CopyImage function in pdf/draw_utils2014-10-08

📋Vendor Advisories

1
Red Hat
chromium: OOB reads in PDFium fixed in Chrome 38.0.2125.1012014-10-07

💬Community

1
Bugzilla
CVE-2014-3189 CVE-2014-3198 chromium: OOB reads in PDFium fixed in Chrome 38.0.2125.1012014-10-10
CVE-2014-3189 — Out-of-bounds Read in Google Chrome | cvebase