ALT-BU-2014-2776-1
Branch sisyphus update bulletin.
Closed vulnerabilities
BDU:2014-00167
Уязвимость браузера Google Chrome, позволяющая злоумышленнику вызвать отказ в обслуживании, связанный с целочисленным переполнением в функциях замены данных
BDU:2014-00199
Уязвимость браузера Google Chrome, позволяющая злоумышленнику вызвать отказ в обслуживании
BDU:2014-00212
Уязвимость браузера Google Chrome, позволяющая злоумышленнику вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2014-1740
Multiple use-after-free vulnerabilities in net/websockets/websocket_job.cc in the WebSockets implementation in Google Chrome before 34.0.1847.137 allow remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to WebSocketJob deletion.
- http://googlechromereleases.blogspot.com/2014/05/stable-channel-update.html
- http://googlechromereleases.blogspot.com/2014/05/stable-channel-update.html
- openSUSE-SU-2014:0783
- openSUSE-SU-2014:0783
- 59155
- 59155
- 60372
- 60372
- GLSA-201408-16
- GLSA-201408-16
- DSA-2930
- DSA-2930
- 67374
- 67374
- 1030240
- 1030240
- https://code.google.com/p/chromium/issues/detail?id=358038
- https://code.google.com/p/chromium/issues/detail?id=358038
- https://src.chromium.org/viewvc/chrome?revision=261707&view=revision
- https://src.chromium.org/viewvc/chrome?revision=261707&view=revision
Modified: 2024-11-21
CVE-2014-1741
Multiple integer overflows in the replace-data functionality in the CharacterData interface implementation in core/dom/CharacterData.cpp in Blink, as used in Google Chrome before 34.0.1847.137, allow remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to ranges.
- http://googlechromereleases.blogspot.com/2014/05/stable-channel-update.html
- http://googlechromereleases.blogspot.com/2014/05/stable-channel-update.html
- openSUSE-SU-2014:0783
- openSUSE-SU-2014:0783
- 59155
- 59155
- 60372
- 60372
- GLSA-201408-16
- GLSA-201408-16
- DSA-2930
- DSA-2930
- 67376
- 67376
- 1030240
- 1030240
- https://code.google.com/p/chromium/issues/detail?id=349898
- https://code.google.com/p/chromium/issues/detail?id=349898
- https://src.chromium.org/viewvc/blink?revision=171165&view=revision
- https://src.chromium.org/viewvc/blink?revision=171165&view=revision
Modified: 2024-11-21
CVE-2014-1742
Use-after-free vulnerability in the FrameSelection::updateAppearance function in core/editing/FrameSelection.cpp in Blink, as used in Google Chrome before 34.0.1847.137, allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging improper RenderObject handling.
- http://googlechromereleases.blogspot.com/2014/05/stable-channel-update.html
- http://googlechromereleases.blogspot.com/2014/05/stable-channel-update.html
- openSUSE-SU-2014:0783
- openSUSE-SU-2014:0783
- 59155
- 59155
- 60372
- 60372
- GLSA-201408-16
- GLSA-201408-16
- DSA-2930
- DSA-2930
- 67375
- 67375
- 1030240
- 1030240
- https://code.google.com/p/chromium/issues/detail?id=356690
- https://code.google.com/p/chromium/issues/detail?id=356690
- https://src.chromium.org/viewvc/blink?revision=171440&view=revision
- https://src.chromium.org/viewvc/blink?revision=171440&view=revision
Closed vulnerabilities
Modified: 2024-11-21
CVE-2014-3441
codec\libpng_plugin.dll in VideoLAN VLC Media Player 2.1.3 allows remote attackers to cause a denial of service (crash) via a crafted .png file, as demonstrated by a png in a .wave file.