Bug 1151395 (CVE-2014-3192) - CVE-2014-3192 chromium: use-after-free in DOM, fixed in Chrome 38.0.2125.101
Summary: CVE-2014-3192 chromium: use-after-free in DOM, fixed in Chrome 38.0.2125.101
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2014-3192
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
urgent
urgent
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1151335 1151338 1163662 1163663
Blocks: 1151371 1205570
TreeView+ depends on / blocked
 
Reported: 2014-10-10 09:57 UTC by Tomas Hoger
Modified: 2021-02-17 06:07 UTC (History)
14 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2015-07-31 05:46:09 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2014:1626 0 normal SHIPPED_LIVE Critical: chromium-browser security update 2014-10-14 11:22:06 UTC

Description Tomas Hoger 2014-10-10 09:57:05 UTC
Use-after-free vulnerability in the ProcessingInstruction::setXSLStyleSheet function in core/dom/ProcessingInstruction.cpp in the DOM implementation in Blink, as used in Google Chrome before 38.0.2125.101, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors. 

https://crbug.com/403276
https://src.chromium.org/viewvc/blink?revision=182309&view=revision

External References:

http://googlechromereleases.blogspot.com/2014/10/stable-channel-update.html

Comment 1 Tomas Hoger 2014-10-10 09:58:22 UTC
Patch also seems applicable to WebKit, but it's unclear if it is really affected too.  I have not looked at any QtWebKit version.

Comment 2 errata-xmlrpc 2014-10-14 08:35:13 UTC
This issue has been addressed in the following products:

  Supplementary for Red Hat Enterprise Linux 6

Via RHSA-2014:1626 https://rhn.redhat.com/errata/RHSA-2014-1626.html

Comment 3 Huzaifa S. Sidhpurwala 2014-11-10 08:12:38 UTC
Upstream patch:

http://src.chromium.org/viewvc/blink?view=revision&revision=182660

Comment 6 Huzaifa S. Sidhpurwala 2015-07-31 05:43:17 UTC
Statement:

This issue affects the versions of webkitgtk and webkitgtk3 as shipped with Red Hat Enterprise Linux 6 and 7 respectively.

Red Hat Product Security has rated this issue as having Moderate security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.


Note You need to log in before you can comment on or make changes to this bug.