MGASA-2014-0183
Dashboard / Vulnerabilities / MGASA-2014-0183
MGASA-2014-0183
Summary: Updated chromium-browser packages fix multiple security vulnerabilities
Details: Updated chromium-browser-stable packages fix security vulnerabilities: Multiple vulnerabilities in the V8 JavaScript library, including a UXSS issue (CVE-2014-1716), OOB access (CVE-2014-1717), memory corruption (CVE-2014-1721), and other vulnerabilities fixed in V8 version 3.24.35.22 (CVE-2014-1729). Integer overflow in compositor (CVE-2014-1718). Multiple use-after-free flaws; in web workers (CVE-2014-1719), DOM (CVE-2014-1720), rendering (CVE-2014-1722), speech (CVE-2014-1724), and forms (CVE-2014-1727). Url confusion with RTL characters (CVE-2014-1723). OOB read with window property (CVE-2014-1725). Local cross-origin bypass (CVE-2014-1726). Various fixes from internal audits, fuzzing and other initiatives (CVE-2014-1728).
References: https://advisories.mageia.org/MGASA-2014-0183.html, http://googlechromereleases.blogspot.com/2014/04/stable-channel-update.html, https://bugs.mageia.org/show_bug.cgi?id=13187
Affected packages
Package
Name: chromium-browser-stable
Purl: pkg:rpm/mageia/chromium-browser-stable?arch=source&distro=mageia-3
Affected ranges
Type: ECOSYSTEM
Events:
