The Instance::HandleInputEvent function in pdf/instance.cc in the PDFium component in Google Chrome prior to 38.0.2125.101 interprets a certain -1 value as an index instead of a no-visible-page error code, which allows remote malicious users to cause a denial of service (out-of-bounds read) via unspecified vectors.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
google chrome |
||
redhat enterprise linux desktop supplementary 6.0 |
||
redhat enterprise linux server supplementary 6.0 |
||
redhat enterprise linux workstation supplementary 6.0 |
||
redhat enterprise linux server supplementary eus 6.6.z |