Red Hat Bugzilla – Bug 1091834
CVE-2014-1730 v8: type confusion issue fixed in Google Chrome 34.0.1847.131
Last modified: 2016-04-26 18:59:13 EDT
Common Vulnerabilities and Exposures assigned an identifier CVE-2014-1730 to the following vulnerability: Name: CVE-2014-1730 URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1730 Assigned: 20140129 Reference: http://googlechromereleases.blogspot.com/2014/04/stable-channel-update_24.html Reference: https://code.google.com/p/chromium/issues/detail?id=354967 Reference: https://code.google.com/p/v8/source/detail?r=20375 Reference: https://code.google.com/p/v8/source/detail?r=20377 Reference: https://code.google.com/p/v8/source/detail?r=20388 Reference: https://code.google.com/p/v8/source/detail?r=20593 Reference: https://code.google.com/p/v8/source/detail?r=20595 Google V8, as used in Google Chrome before 34.0.1847.131 on Windows and OS X and before 34.0.1847.132 on Linux, does not properly store internationalization metadata, which allows remote attackers to bypass intended access restrictions by leveraging "type confusion" and reading property values, related to i18n.js and runtime.cc. It appears as though the Fedora packages may not be affected.
Not applicable to v8 3.14.