Candidate: CVE-2014-7905 PublicDate: 2014-11-19 11:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-7905 https://code.google.com/p/chromium/issues/detail?id=421817 (private) https://code.google.com/p/chromium/issues/detail?id=421817 http://googlechromereleases.blogspot.com/2014/11/stable-channel-update_18.html Description: Google Chrome before 39.0.2171.65 on Android does not prevent navigation to a URL in cases where an intent for the URL lacks CATEGORY_BROWSABLE, which allows remote attackers to bypass intended access restrictions via a crafted web site. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: Patches_chromium-browser: upstream_chromium-browser: released (39.0.2171.65) lucid_chromium-browser: ignored (reached end-of-life) precise_chromium-browser: ignored trusty_chromium-browser: released (39.0.2171.65-0ubuntu0.14.04.1.1064) trusty/esm_chromium-browser: DNE (trusty was released [39.0.2171.65-0ubuntu0.14.04.1.1064]) utopic_chromium-browser: released (39.0.2171.65-0ubuntu0.14.10.1.1106) vivid_chromium-browser: released (39.0.2171.65-0ubuntu1.1108) wily_chromium-browser: released (39.0.2171.65-0ubuntu1.1108) devel_chromium-browser: released (39.0.2171.65-0ubuntu1.1108) Patches_oxide-qt: upstream_oxide-qt: released (1.3.4) lucid_oxide-qt: DNE precise_oxide-qt: DNE trusty_oxide-qt: not-affected trusty/esm_oxide-qt: DNE (trusty was not-affected) utopic_oxide-qt: not-affected vivid_oxide-qt: not-affected wily_oxide-qt: not-affected devel_oxide-qt: not-affected