Unspecified use-after-free vulnerability has been found [1] in Chromium pepper plugins. [1]: https://code.google.com/p/chromium/issues/detail?id=423030 External References: http://googlechromereleases.blogspot.com/2014/11/stable-channel-update_18.html
Statement: (none)
I dont have access to the upstream bug. However it seems this is related to https://chromium.googlesource.com/chromium/src/+/db8e2abccd737b0513a2cd11add50b543783f2da Tomas, confirmed this is a part of the code we ship, calling it affected.
This issue has been addressed in the following products: Supplementary for Red Hat Enterprise Linux 6 Via RHSA-2014:1894 https://rhn.redhat.com/errata/RHSA-2014-1894.html
Why were we Qt/KDE maintainers put on CC for this bug? This is clearly a Chromium-specific vulnerability that cannot possibly affect QtWebKit or KHTML (because neither supports Pepper plugins). Only QtWebEngine can possibly be affected, but it is not currently in Fedora.