ALT-BU-2014-2752-1
Branch p7 update bulletin.
Closed vulnerabilities
BDU:2014-00115
Уязвимость браузера Google Chrome, позволяющая злоумышленнику вызвать отказ в обслуживании
BDU:2014-00116
Уязвимость браузера Google Chrome, позволяющая злоумышленнику вызвать отказ в обслуживании
BDU:2014-00126
Уязвимость браузера Google Chrome, позволяющая злоумышленнику вызвать отказ в обслуживании
BDU:2014-00133
Уязвимость браузера Google Chrome, позволяющая злоумышленнику вызвать отказ в обслуживании
BDU:2014-00142
Уязвимость браузера Google Chrome, позволяющая злоумышленнику обойти правила ограничения домена
BDU:2014-00145
Уязвимость браузера Google Chrome, позволяющая злоумышленнику внедрить произвольный веб-сценарий или HTML-код
BDU:2014-00152
Уязвимость браузера Google Chrome, позволяющая злоумышленнику вызвать отказ в обслуживании
BDU:2014-00156
Уязвимость браузера Google Chrome, позволяющая злоумышленнику вызвать отказ в обслуживании
BDU:2014-00168
Уязвимость браузера Google Chrome, позволяющая злоумышленнику вызвать отказ в обслуживании
BDU:2014-00173
Уязвимость браузера Google Chrome, позволяющая злоумышленнику обойти ограничения песочницы
BDU:2014-00175
Уязвимость браузера Google Chrome, позволяющая злоумышленнику подменить URL-адреса
BDU:2014-00178
Уязвимость браузера Google Chrome, позволяющая злоумышленнику вызвать отказ в обслуживании
BDU:2014-00181
Уязвимость браузера Google Chrome, позволяющая злоумышленнику вызвать отказ в обслуживании
BDU:2014-00187
Уязвимость браузера Google Chrome, позволяющая злоумышленнику вызвать отказ в обслуживании
BDU:2014-00200
Уязвимость браузера Google Chrome, позволяющая злоумышленнику вызвать отказ в обслуживании
BDU:2015-00099
Уязвимость браузера Google Chrome, позволяющая злоумышленнику обойти ограничения песочницы
BDU:2015-00100
Уязвимость браузера Google Chrome, позволяющая злоумышленнику вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2014-1716
Cross-site scripting (XSS) vulnerability in the Runtime_SetPrototype function in runtime.cc in Google V8, as used in Google Chrome before 34.0.1847.116, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Universal XSS (UXSS)."
- http://googlechromereleases.blogspot.com/2014/04/stable-channel-update.html
- http://googlechromereleases.blogspot.com/2014/04/stable-channel-update.html
- openSUSE-SU-2014:0601
- openSUSE-SU-2014:0601
- GLSA-201408-16
- GLSA-201408-16
- DSA-2905
- DSA-2905
- https://code.google.com/p/chromium/issues/detail?id=354123
- https://code.google.com/p/chromium/issues/detail?id=354123
- https://code.google.com/p/v8/source/detail?r=20138
- https://code.google.com/p/v8/source/detail?r=20138
Modified: 2024-11-21
CVE-2014-1717
Google V8, as used in Google Chrome before 34.0.1847.116, does not properly use numeric casts during handling of typed arrays, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted JavaScript code.
- http://googlechromereleases.blogspot.com/2014/04/stable-channel-update.html
- http://googlechromereleases.blogspot.com/2014/04/stable-channel-update.html
- openSUSE-SU-2014:0601
- openSUSE-SU-2014:0601
- GLSA-201408-16
- GLSA-201408-16
- DSA-2905
- DSA-2905
- https://code.google.com/p/chromium/issues/detail?id=353004
- https://code.google.com/p/chromium/issues/detail?id=353004
- https://code.google.com/p/v8/source/detail?r=20020
- https://code.google.com/p/v8/source/detail?r=20020
Modified: 2024-11-21
CVE-2014-1718
Integer overflow in the SoftwareFrameManager::SwapToNewFrame function in content/browser/renderer_host/software_frame_manager.cc in the software compositor in Google Chrome before 34.0.1847.116 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger an attempted mapping of a large amount of renderer memory.
- http://googlechromereleases.blogspot.com/2014/04/stable-channel-update.html
- http://googlechromereleases.blogspot.com/2014/04/stable-channel-update.html
- openSUSE-SU-2014:0601
- openSUSE-SU-2014:0601
- GLSA-201408-16
- GLSA-201408-16
- DSA-2905
- DSA-2905
- https://code.google.com/p/chromium/issues/detail?id=348332
- https://code.google.com/p/chromium/issues/detail?id=348332
- https://src.chromium.org/viewvc/chrome?revision=257417&view=revision
- https://src.chromium.org/viewvc/chrome?revision=257417&view=revision
- https://src.chromium.org/viewvc/chrome?revision=258418&view=revision
- https://src.chromium.org/viewvc/chrome?revision=258418&view=revision
- https://src.chromium.org/viewvc/chrome?revision=260969&view=revision
- https://src.chromium.org/viewvc/chrome?revision=260969&view=revision
- https://src.chromium.org/viewvc/chrome?revision=261817&view=revision
- https://src.chromium.org/viewvc/chrome?revision=261817&view=revision
Modified: 2024-11-21
CVE-2014-1719
Use-after-free vulnerability in the WebSharedWorkerStub::OnTerminateWorkerContext function in content/worker/websharedworker_stub.cc in the Web Workers implementation in Google Chrome before 34.0.1847.116 allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via vectors that trigger a SharedWorker termination during script loading.
- http://googlechromereleases.blogspot.com/2014/04/stable-channel-update.html
- http://googlechromereleases.blogspot.com/2014/04/stable-channel-update.html
- openSUSE-SU-2014:0601
- openSUSE-SU-2014:0601
- GLSA-201408-16
- GLSA-201408-16
- DSA-2905
- DSA-2905
- https://code.google.com/p/chromium/issues/detail?id=343661
- https://code.google.com/p/chromium/issues/detail?id=343661
- https://src.chromium.org/viewvc/chrome?revision=252010&view=revision
- https://src.chromium.org/viewvc/chrome?revision=252010&view=revision
Modified: 2024-11-21
CVE-2014-1720
Use-after-free vulnerability in the HTMLBodyElement::insertedInto function in core/html/HTMLBodyElement.cpp in Blink, as used in Google Chrome before 34.0.1847.116, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving attributes.
- http://googlechromereleases.blogspot.com/2014/04/stable-channel-update.html
- http://googlechromereleases.blogspot.com/2014/04/stable-channel-update.html
- openSUSE-SU-2014:0601
- openSUSE-SU-2014:0601
- GLSA-201408-16
- GLSA-201408-16
- DSA-2905
- DSA-2905
- https://code.google.com/p/chromium/issues/detail?id=356095
- https://code.google.com/p/chromium/issues/detail?id=356095
- https://src.chromium.org/viewvc/blink?revision=170216&view=revision
- https://src.chromium.org/viewvc/blink?revision=170216&view=revision
Modified: 2024-11-21
CVE-2014-1721
Google V8, as used in Google Chrome before 34.0.1847.116, does not properly implement lazy deoptimization, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via crafted JavaScript code, as demonstrated by improper handling of a heap allocation of a number outside the Small Integer (aka smi) range.
- http://googlechromereleases.blogspot.com/2014/04/stable-channel-update.html
- http://googlechromereleases.blogspot.com/2014/04/stable-channel-update.html
- openSUSE-SU-2014:0601
- openSUSE-SU-2014:0601
- GLSA-201408-16
- GLSA-201408-16
- DSA-2905
- DSA-2905
- https://code.google.com/p/chromium/issues/detail?id=350434
- https://code.google.com/p/chromium/issues/detail?id=350434
- https://code.google.com/p/v8/source/detail?r=19834
- https://code.google.com/p/v8/source/detail?r=19834
Modified: 2024-11-21
CVE-2014-1722
Use-after-free vulnerability in the RenderBlock::addChildIgnoringAnonymousColumnBlocks function in core/rendering/RenderBlock.cpp in Blink, as used in Google Chrome before 34.0.1847.116, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving addition of a child node.
- http://googlechromereleases.blogspot.com/2014/04/stable-channel-update.html
- http://googlechromereleases.blogspot.com/2014/04/stable-channel-update.html
- openSUSE-SU-2014:0601
- openSUSE-SU-2014:0601
- GLSA-201408-16
- GLSA-201408-16
- DSA-2905
- DSA-2905
- https://code.google.com/p/chromium/issues/detail?id=330626
- https://code.google.com/p/chromium/issues/detail?id=330626
- https://src.chromium.org/viewvc/blink?revision=164405&view=revision
- https://src.chromium.org/viewvc/blink?revision=164405&view=revision
Modified: 2024-11-21
CVE-2014-1723
The UnescapeURLWithOffsetsImpl function in net/base/escape.cc in Google Chrome before 34.0.1847.116 does not properly handle bidirectional Internationalized Resource Identifiers (IRIs), which makes it easier for remote attackers to spoof URLs via crafted use of right-to-left (RTL) Unicode text.
- http://googlechromereleases.blogspot.com/2014/04/stable-channel-update.html
- http://googlechromereleases.blogspot.com/2014/04/stable-channel-update.html
- openSUSE-SU-2014:0601
- openSUSE-SU-2014:0601
- GLSA-201408-16
- GLSA-201408-16
- DSA-2905
- DSA-2905
- https://code.google.com/p/chromium/issues/detail?id=337746
- https://code.google.com/p/chromium/issues/detail?id=337746
- https://src.chromium.org/viewvc/chrome?revision=254091&view=revision
- https://src.chromium.org/viewvc/chrome?revision=254091&view=revision
Modified: 2024-11-21
CVE-2014-1724
Use-after-free vulnerability in Free(b)soft Laboratory Speech Dispatcher 0.7.1, as used in Google Chrome before 34.0.1847.116, allows remote attackers to cause a denial of service (application hang) or possibly have unspecified other impact via a text-to-speech request.
- http://googlechromereleases.blogspot.com/2014/04/stable-channel-update.html
- http://googlechromereleases.blogspot.com/2014/04/stable-channel-update.html
- openSUSE-SU-2014:0601
- openSUSE-SU-2014:0601
- GLSA-201408-16
- GLSA-201408-16
- DSA-2905
- DSA-2905
- https://code.google.com/p/chromium/issues/detail?id=327295
- https://code.google.com/p/chromium/issues/detail?id=327295
- https://src.chromium.org/viewvc/chrome?revision=259109&view=revision
- https://src.chromium.org/viewvc/chrome?revision=259109&view=revision
Modified: 2024-11-21
CVE-2014-1725
The base64DecodeInternal function in wtf/text/Base64.cpp in Blink, as used in Google Chrome before 34.0.1847.116, does not properly handle string data composed exclusively of whitespace characters, which allows remote attackers to cause a denial of service (out-of-bounds read) via a window.atob method call.
- http://googlechromereleases.blogspot.com/2014/04/stable-channel-update.html
- http://googlechromereleases.blogspot.com/2014/04/stable-channel-update.html
- openSUSE-SU-2014:0601
- openSUSE-SU-2014:0601
- GLSA-201408-16
- GLSA-201408-16
- DSA-2905
- DSA-2905
- https://code.google.com/p/chromium/issues/detail?id=357332
- https://code.google.com/p/chromium/issues/detail?id=357332
- https://src.chromium.org/viewvc/blink?revision=170264&view=revision
- https://src.chromium.org/viewvc/blink?revision=170264&view=revision
Modified: 2024-11-21
CVE-2014-1726
The drag implementation in Google Chrome before 34.0.1847.116 allows user-assisted remote attackers to bypass the Same Origin Policy and forge local pathnames by leveraging renderer access.
- http://googlechromereleases.blogspot.com/2014/04/stable-channel-update.html
- http://googlechromereleases.blogspot.com/2014/04/stable-channel-update.html
- openSUSE-SU-2014:0601
- openSUSE-SU-2014:0601
- GLSA-201408-16
- GLSA-201408-16
- DSA-2905
- DSA-2905
- https://code.google.com/p/chromium/issues/detail?id=346135
- https://code.google.com/p/chromium/issues/detail?id=346135
- https://src.chromium.org/viewvc/chrome?revision=259353&view=revision
- https://src.chromium.org/viewvc/chrome?revision=259353&view=revision
Modified: 2024-11-21
CVE-2014-1727
Use-after-free vulnerability in content/renderer/renderer_webcolorchooser_impl.h in Google Chrome before 34.0.1847.116 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to forms.
- http://googlechromereleases.blogspot.com/2014/04/stable-channel-update.html
- http://googlechromereleases.blogspot.com/2014/04/stable-channel-update.html
- openSUSE-SU-2014:0601
- openSUSE-SU-2014:0601
- GLSA-201408-16
- GLSA-201408-16
- DSA-2905
- DSA-2905
- https://code.google.com/p/chromium/issues/detail?id=342735
- https://code.google.com/p/chromium/issues/detail?id=342735
- https://src.chromium.org/viewvc/chrome?revision=255276&view=revision
- https://src.chromium.org/viewvc/chrome?revision=255276&view=revision
Modified: 2024-11-21
CVE-2014-1728
Multiple unspecified vulnerabilities in Google Chrome before 34.0.1847.116 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
- http://googlechromereleases.blogspot.com/2014/04/stable-channel-update.html
- http://googlechromereleases.blogspot.com/2014/04/stable-channel-update.html
- openSUSE-SU-2014:0601
- openSUSE-SU-2014:0601
- GLSA-201408-16
- GLSA-201408-16
- DSA-2905
- DSA-2905
- https://code.google.com/p/chromium/issues/detail?id=345820
- https://code.google.com/p/chromium/issues/detail?id=345820
- https://code.google.com/p/chromium/issues/detail?id=347262
- https://code.google.com/p/chromium/issues/detail?id=347262
- https://code.google.com/p/chromium/issues/detail?id=348319
- https://code.google.com/p/chromium/issues/detail?id=348319
- https://code.google.com/p/chromium/issues/detail?id=350533
- https://code.google.com/p/chromium/issues/detail?id=350533
- https://code.google.com/p/chromium/issues/detail?id=350537
- https://code.google.com/p/chromium/issues/detail?id=350537
- https://code.google.com/p/chromium/issues/detail?id=350863
- https://code.google.com/p/chromium/issues/detail?id=350863
- https://code.google.com/p/chromium/issues/detail?id=351815
- https://code.google.com/p/chromium/issues/detail?id=351815
- https://code.google.com/p/chromium/issues/detail?id=352982
- https://code.google.com/p/chromium/issues/detail?id=352982
- https://code.google.com/p/chromium/issues/detail?id=353013
- https://code.google.com/p/chromium/issues/detail?id=353013
- https://code.google.com/p/chromium/issues/detail?id=354297
- https://code.google.com/p/chromium/issues/detail?id=354297
- https://code.google.com/p/chromium/issues/detail?id=355586
- https://code.google.com/p/chromium/issues/detail?id=355586
- https://code.google.com/p/chromium/issues/detail?id=356235
- https://code.google.com/p/chromium/issues/detail?id=356235
- https://code.google.com/p/chromium/issues/detail?id=356517
- https://code.google.com/p/chromium/issues/detail?id=356517
- https://code.google.com/p/chromium/issues/detail?id=358059
- https://code.google.com/p/chromium/issues/detail?id=358059
- https://code.google.com/p/chromium/issues/detail?id=360298
- https://code.google.com/p/chromium/issues/detail?id=360298
Modified: 2024-11-21
CVE-2014-1729
Multiple unspecified vulnerabilities in Google V8 before 3.24.35.22, as used in Google Chrome before 34.0.1847.116, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
- http://googlechromereleases.blogspot.com/2014/04/stable-channel-update.html
- http://googlechromereleases.blogspot.com/2014/04/stable-channel-update.html
- openSUSE-SU-2014:0601
- openSUSE-SU-2014:0601
- GLSA-201408-16
- GLSA-201408-16
- DSA-2905
- DSA-2905
- https://code.google.com/p/chromium/issues/detail?id=345820
- https://code.google.com/p/chromium/issues/detail?id=345820
- https://code.google.com/p/chromium/issues/detail?id=347262
- https://code.google.com/p/chromium/issues/detail?id=347262
- https://code.google.com/p/chromium/issues/detail?id=348319
- https://code.google.com/p/chromium/issues/detail?id=348319
- https://code.google.com/p/chromium/issues/detail?id=350863
- https://code.google.com/p/chromium/issues/detail?id=350863
- https://code.google.com/p/chromium/issues/detail?id=352982
- https://code.google.com/p/chromium/issues/detail?id=352982
- https://code.google.com/p/chromium/issues/detail?id=355586
- https://code.google.com/p/chromium/issues/detail?id=355586
- https://code.google.com/p/chromium/issues/detail?id=358059
- https://code.google.com/p/chromium/issues/detail?id=358059
- https://code.google.com/p/v8/source/detail?r=19572
- https://code.google.com/p/v8/source/detail?r=19572
- https://code.google.com/p/v8/source/detail?r=19584
- https://code.google.com/p/v8/source/detail?r=19584
- https://code.google.com/p/v8/source/detail?r=19923
- https://code.google.com/p/v8/source/detail?r=19923
- https://code.google.com/p/v8/source/detail?r=20033
- https://code.google.com/p/v8/source/detail?r=20033
- https://code.google.com/p/v8/source/detail?r=20345
- https://code.google.com/p/v8/source/detail?r=20345
- https://code.google.com/p/v8/source/detail?r=20409
- https://code.google.com/p/v8/source/detail?r=20409
Modified: 2024-11-21
CVE-2014-1731
core/html/HTMLSelectElement.cpp in the DOM implementation in Blink, as used in Google Chrome before 34.0.1847.131 on Windows and OS X and before 34.0.1847.132 on Linux, does not properly check renderer state upon a focus event, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that leverage "type confusion" for SELECT elements.
- APPLE-SA-2014-05-21-1
- APPLE-SA-2014-05-21-1
- APPLE-SA-2014-06-30-3
- APPLE-SA-2014-06-30-3
- APPLE-SA-2014-06-30-4
- APPLE-SA-2014-06-30-4
- http://googlechromereleases.blogspot.com/2014/04/stable-channel-update_24.html
- http://googlechromereleases.blogspot.com/2014/04/stable-channel-update_24.html
- openSUSE-SU-2014:0668
- openSUSE-SU-2014:0668
- openSUSE-SU-2014:0669
- openSUSE-SU-2014:0669
- 58301
- 58301
- 60372
- 60372
- GLSA-201408-16
- GLSA-201408-16
- http://support.apple.com/kb/HT6254
- http://support.apple.com/kb/HT6254
- DSA-2920
- DSA-2920
- 67572
- 67572
- https://code.google.com/p/chromium/issues/detail?id=349903
- https://code.google.com/p/chromium/issues/detail?id=349903
- https://src.chromium.org/viewvc/blink?revision=171216&view=revision
- https://src.chromium.org/viewvc/blink?revision=171216&view=revision
- https://support.apple.com/kb/HT6537
- https://support.apple.com/kb/HT6537
Modified: 2024-11-21
CVE-2014-1732
Use-after-free vulnerability in browser/ui/views/speech_recognition_bubble_views.cc in Google Chrome before 34.0.1847.131 on Windows and OS X and before 34.0.1847.132 on Linux allows remote attackers to cause a denial of service or possibly have unspecified other impact via an INPUT element that triggers the presence of a Speech Recognition Bubble window for an incorrect duration.
- http://googlechromereleases.blogspot.com/2014/04/stable-channel-update_24.html
- http://googlechromereleases.blogspot.com/2014/04/stable-channel-update_24.html
- openSUSE-SU-2014:0668
- openSUSE-SU-2014:0668
- openSUSE-SU-2014:0669
- openSUSE-SU-2014:0669
- 58301
- 58301
- GLSA-201408-16
- GLSA-201408-16
- DSA-2920
- DSA-2920
- https://code.google.com/p/chromium/issues/detail?id=352851
- https://code.google.com/p/chromium/issues/detail?id=352851
- https://src.chromium.org/viewvc/chrome?revision=261737&view=revision
- https://src.chromium.org/viewvc/chrome?revision=261737&view=revision
Modified: 2024-11-21
CVE-2014-1733
The PointerCompare function in codegen.cc in Seccomp-BPF, as used in Google Chrome before 34.0.1847.131 on Windows and OS X and before 34.0.1847.132 on Linux, does not properly merge blocks, which might allow remote attackers to bypass intended sandbox restrictions by leveraging renderer access.
- http://googlechromereleases.blogspot.com/2014/04/stable-channel-update_24.html
- http://googlechromereleases.blogspot.com/2014/04/stable-channel-update_24.html
- openSUSE-SU-2014:0668
- openSUSE-SU-2014:0668
- openSUSE-SU-2014:0669
- openSUSE-SU-2014:0669
- 58301
- 58301
- GLSA-201408-16
- GLSA-201408-16
- DSA-2920
- DSA-2920
- https://code.google.com/p/chromium/issues/detail?id=351103
- https://code.google.com/p/chromium/issues/detail?id=351103
- https://src.chromium.org/viewvc/chrome?revision=260157&view=revision
- https://src.chromium.org/viewvc/chrome?revision=260157&view=revision
Closed bugs
Мелкие ошибки в Chromium версия 21.0.1180.89 ALT Linux (154005)
Closed vulnerabilities
Modified: 2024-11-21
CVE-2013-5919
Suricata before 1.4.6 allows remote attackers to cause a denial of service (crash) via a malformed SSL record.
Package smartmontools updated to version 6.2-alt0.M70P.1 for branch p7 in task 119223.
Closed bugs
Просьба обновить версию.