Bug 1151422 (CVE-2014-3197)

Summary: CVE-2014-3197 chromium: information leak in XSS Auditor fixed in Chrome 38.0.2125.101
Product: [Other] Security Response Reporter: Tomas Hoger <thoger>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: fedora, huzaifas, jgrulich, jreznik, jrusnack, kalevlember, kevin, kevin, ltinkl, martin.sourada, mclasen, mtasaka, rdieter, rnovacek, than, tpopela
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2014-10-14 08:47:05 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1151335, 1151338    
Bug Blocks: 1151371    

Description Tomas Hoger 2014-10-10 11:20:59 UTC
The NavigationScheduler::schedulePageBlock function in core/loader/NavigationScheduler.cpp in Blink, as used in Google Chrome before 38.0.2125.101, does not properly provide substitute data for pages blocked by the XSS auditor, which allows remote attackers to obtain sensitive information via a crafted web site.

https://crbug.com/396544
https://src.chromium.org/viewvc/blink?revision=179240&view=revision

External References:

http://googlechromereleases.blogspot.com/2014/10/stable-channel-update.html

Comment 1 Tomas Hoger 2014-10-10 11:23:17 UTC
While WebKit contains NavigationScheduler, it does not seem to contain functionality corrected by the fix for this issue.  Note that XSS auditor is feature of the Chrome/Chromium browser, hence consider WebKitGTK versions unaffected.  I haven't investigated QtWebKit, it's likely unaffected too.

Comment 2 errata-xmlrpc 2014-10-14 08:35:15 UTC
This issue has been addressed in the following products:

  Supplementary for Red Hat Enterprise Linux 6

Via RHSA-2014:1626 https://rhn.redhat.com/errata/RHSA-2014-1626.html