CVE-2014-1726

Publication date 9 April 2014

Last updated 24 July 2024


Ubuntu priority

The drag implementation in Google Chrome before 34.0.1847.116 allows user-assisted remote attackers to bypass the Same Origin Policy and forge local pathnames by leveraging renderer access.

Read the notes from the security team

Status

Package Ubuntu Release Status
chromium-browser 14.04 LTS trusty Not in release
13.10 saucy
Fixed 34.0.1847.116-0ubuntu~1.13.10.0~pkg991
12.10 quantal
Fixed 34.0.1847.116-0ubuntu~1.12.10.0~pkg900
12.04 LTS precise
Fixed 34.0.1847.116-0ubuntu~1.12.04.0~pkg884
10.04 LTS lucid Ignored end of life
oxide-qt 14.04 LTS trusty Not in release
13.10 saucy Not in release
12.10 quantal Not in release
12.04 LTS precise Not in release
10.04 LTS lucid Not in release

Notes


chrisccoulson

Drag / drop currently not implemented in Oxide