Red Hat Bugzilla – Bug 1151383
CVE-2014-3194 chromium: use-after-free issue in Web Workers fixed in Chrome 38.0.2125.101
Last modified: 2015-11-25 05:14:50 EST
Use-after-free vulnerability in the Web Workers implementation in Google Chrome before 38.0.2125.101 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors. https://crbug.com/401115 External References: http://googlechromereleases.blogspot.com/2014/10/stable-channel-update.html
Upstream bug is close, there does not seem to be any details available for this flaw. It's currently unclear if this may affect any WebKit version.
This issue has been addressed in the following products: Supplementary for Red Hat Enterprise Linux 6 Via RHSA-2014:1626 https://rhn.redhat.com/errata/RHSA-2014-1626.html
Upstream commit: http://src.chromium.org/viewvc/blink?view=revision&revision=182647
This issue seems to be specific to the chromium-browser and hence does not affect webkitgtk in Red Hat Enterprise Linux. Statement: Not vulnerable. This issue does not affect the version of webkitgtk as shipped with Red Hat Enterprise Linux 6 and 7. This issue does not affect the version of webkitgtk3 as shipped with Red Hat Enterprise Linux 7.