PublicDateAtUSN: 2014-10-08 Candidate: CVE-2014-3191 PublicDate: 2014-10-08 10:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3191 https://src.chromium.org/viewvc/blink?revision=180681&view=revision https://crbug.com/402407 http://googlechromereleases.blogspot.com/2014/10/stable-channel-update.html https://ubuntu.com/security/notices/USN-2345-1 Description: Use-after-free vulnerability in Blink, as used in Google Chrome before 38.0.2125.101, allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code that triggers a widget-position update that improperly interacts with the render tree, related to the FrameView::updateLayoutAndStyleForPainting function in core/frame/FrameView.cpp and the RenderLayerScrollableArea::setScrollOffset function in core/rendering/RenderLayerScrollableArea.cpp. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: Patches_chromium-browser: upstream_chromium-browser: released (38.0.2125.101) lucid_chromium-browser: ignored (reached end-of-life) precise_chromium-browser: ignored trusty_chromium-browser: released (38.0.2125.111-0ubuntu0.14.04.1.1061) trusty/esm_chromium-browser: DNE (trusty was released [38.0.2125.111-0ubuntu0.14.04.1.1061]) utopic_chromium-browser: released (38.0.2125.111-0ubuntu0.14.10.1.1103) vivid_chromium-browser: released (38.0.2125.111-0ubuntu1.1103) wily_chromium-browser: released (38.0.2125.111-0ubuntu1.1103) devel_chromium-browser: released (38.0.2125.111-0ubuntu1.1103) Patches_oxide-qt: upstream_oxide-qt: released (1.2.5) lucid_oxide-qt: DNE precise_oxide-qt: DNE trusty_oxide-qt: released (1.2.5-0ubuntu0.14.04.1) trusty/esm_oxide-qt: DNE (trusty was released [1.2.5-0ubuntu0.14.04.1]) utopic_oxide-qt: released (1.2.5-0ubuntu1) vivid_oxide-qt: released (1.2.5-0ubuntu1) wily_oxide-qt: released (1.2.5-0ubuntu1) devel_oxide-qt: released (1.2.5-0ubuntu1)