Candidate: CVE-2014-1725 PublicDate: 2014-04-09 10:57:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1725 https://src.chromium.org/viewvc/blink?revision=170264&view=revision https://code.google.com/p/chromium/issues/detail?id=357332 http://googlechromereleases.blogspot.com/2014/04/stable-channel-update.html Description: The base64DecodeInternal function in wtf/text/Base64.cpp in Blink, as used in Google Chrome before 34.0.1847.116, does not properly handle string data composed exclusively of whitespace characters, which allows remote attackers to cause a denial of service (out-of-bounds read) via a window.atob method call. Ubuntu-Description: Notes: chrisccoulson> Issue was fixed prior to Oxide r501, the first version to be included in an Ubuntu release Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: Patches_chromium-browser: upstream_chromium-browser: released (34.0.1847.116) lucid_chromium-browser: ignored (reached end-of-life) precise_chromium-browser: released (34.0.1847.116-0ubuntu~1.12.04.0~pkg884) quantal_chromium-browser: released (34.0.1847.116-0ubuntu~1.12.10.0~pkg900) saucy_chromium-browser: released (34.0.1847.116-0ubuntu~1.13.10.0~pkg991) trusty_chromium-browser: not-affected (34.0.1847.116-0ubuntu2) trusty/esm_chromium-browser: DNE (trusty was not-affected [34.0.1847.116-0ubuntu2]) devel_chromium-browser: not-affected (34.0.1847.116-0ubuntu2) Patches_oxide-qt: upstream_oxide-qt: not-affected lucid_oxide-qt: DNE precise_oxide-qt: DNE quantal_oxide-qt: DNE saucy_oxide-qt: DNE trusty_oxide-qt: not-affected trusty/esm_oxide-qt: DNE (trusty was not-affected) devel_oxide-qt: not-affected