Endpoint Vulnerability

Security Vulnerability CVE-2014-3198 for Google Chrome

Description

The Instance::HandleInputEvent function in pdf/instance.cc in the PDFium component in Google Chrome before 38.0.2125.101 interprets a certain -1 value as an index instead of a no-visible-page error code, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

Affected Products

Google Chrome

References

CVE-2014-3198,