CVE-2014-1730

Priority
Medium
Description
Google V8, as used in Google Chrome before 34.0.1847.131 on Windows and OS
X and before 34.0.1847.132 on Linux, does not properly store
internationalization metadata, which allows remote attackers to bypass
intended access restrictions by leveraging "type confusion" and reading
property values, related to i18n.js and runtime.cc.
References
Package
Upstream:released (34.0.1847.132)
Ubuntu 10.04 LTS (Lucid Lynx):ignored (reached end-of-life)
Ubuntu 12.04 LTS (Precise Pangolin):released (36.0.1985.125-0ubuntu1.12.04.0~pkg897)
Ubuntu 14.04 LTS (Trusty Tahr):released (36.0.1985.125-0ubuntu1.14.04.0~pkg1029)
Ubuntu 14.10 (Utopic Unicorn):released (35.0.1916.153-0ubuntu1~pkg1029)
Ubuntu 15.04 (Vivid Vervet):released (35.0.1916.153-0ubuntu1~pkg1029)
Package
Upstream:needed
Ubuntu 10.04 LTS (Lucid Lynx):DNE
Ubuntu 12.04 LTS (Precise Pangolin):DNE
Ubuntu 14.04 LTS (Trusty Tahr):needs-triage
Ubuntu 14.10 (Utopic Unicorn):needs-triage
Ubuntu 15.04 (Vivid Vervet):needs-triage
Package
Source: libv8 (LP Ubuntu Debian)
Upstream:needs-triage
Ubuntu 10.04 LTS (Lucid Lynx):ignored (reached end-of-life)
Ubuntu 12.04 LTS (Precise Pangolin):needs-triage
Ubuntu 14.04 LTS (Trusty Tahr):DNE
Ubuntu 14.10 (Utopic Unicorn):DNE
Ubuntu 15.04 (Vivid Vervet):DNE
Package
Upstream:released (1.0.4)
Ubuntu 10.04 LTS (Lucid Lynx):DNE
Ubuntu 12.04 LTS (Precise Pangolin):DNE
Ubuntu 14.04 LTS (Trusty Tahr):released (1.0.4-0ubuntu0.14.04.1)
Ubuntu 14.10 (Utopic Unicorn):released (1.1.0~bzr540-0ubuntu1)
Ubuntu 15.04 (Vivid Vervet):released (1.1.0~bzr540-0ubuntu1)
More Information

Valid XHTML 1.0 Strict

Updated: 2015-04-30 14:14:35 UTC (commit 9405)