UBUNTU-CVE-2014-1730
Dashboard / Vulnerabilities / UBUNTU-CVE-2014-1730
UBUNTU-CVE-2014-1730
Summary:
Details: Google V8, as used in Google Chrome before 34.0.1847.131 on Windows and OS X and before 34.0.1847.132 on Linux, does not properly store internationalization metadata, which allows remote attackers to bypass intended access restrictions by leveraging "type confusion" and reading property values, related to i18n.js and runtime.cc.
References: https://ubuntu.com/security/CVE-2014-1730, https://code.google.com/p/v8/source/detail?r=20595, https://code.google.com/p/v8/source/detail?r=20593, https://code.google.com/p/v8/source/detail?r=20388, https://code.google.com/p/v8/source/detail?r=20377, https://code.google.com/p/v8/source/detail?r=20375, https://code.google.com/p/chromium/issues/detail?id=354967, http://googlechromereleases.blogspot.com/2014/04/stable-channel-update_24.html, https://ubuntu.com/security/notices/USN-2298-1, https://www.cve.org/CVERecord?id=CVE-2014-1730
Affected packages
Package
Name: chromium-browser
Purl: pkg:deb/ubuntu/[email protected]~pkg1029?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
