CVE-2014-1713
Publication date 16 March 2014
Last updated 24 July 2024
Ubuntu priority
Use-after-free vulnerability in the AttributeSetter function in bindings/templates/attributes.cpp in the bindings in Blink, as used in Google Chrome before 33.0.1750.152 on OS X and Linux and before 33.0.1750.154 on Windows, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving the document.location value.
Status
Package | Ubuntu Release | Status |
---|---|---|
chromium-browser | 13.10 saucy |
Fixed 33.0.1750.152-0ubuntu0.13.10.1~pkg984.1
|
12.10 quantal |
Fixed 33.0.1750.152-0ubuntu0.12.10.1~pkg895.1
|
|
12.04 LTS precise |
Fixed 33.0.1750.152-0ubuntu0.12.04.1~pkg879.1
|
|
10.04 LTS lucid | Ignored end of life | |
oxide-qt | 13.10 saucy | Not in release |
12.10 quantal | Not in release | |
12.04 LTS precise | Not in release | |
10.04 LTS lucid | Not in release |
References
Other references
- https://src.chromium.org/viewvc/blink?revision=169176&view=revision
- https://code.google.com/p/chromium/issues/detail?id=352374
- http://googlechromereleases.blogspot.com/2014/03/stable-channel-update_14.html
- http://googlechromereleases.blogspot.com/2014/03/stable-channel-update-for-chrome-os_14.html
- https://www.cve.org/CVERecord?id=CVE-2014-1713