CVE-2014-3197

Publication date 8 October 2014

Last updated 24 July 2024


Ubuntu priority

The NavigationScheduler::schedulePageBlock function in core/loader/NavigationScheduler.cpp in Blink, as used in Google Chrome before 38.0.2125.101, does not properly provide substitute data for pages blocked by the XSS auditor, which allows remote attackers to obtain sensitive information via a crafted web site.

Status

Package Ubuntu Release Status
chromium-browser 14.04 LTS trusty Not in release
12.04 LTS precise
Not affected
10.04 LTS lucid Ignored end of life
oxide-qt 14.04 LTS trusty
Fixed 1.2.5-0ubuntu0.14.04.1
12.04 LTS precise Not in release
10.04 LTS lucid Not in release