ALT-BU-2014-2907-1
Branch t7 update bulletin.
Closed vulnerabilities
BDU:2014-00137
Уязвимость браузера Google Chrome, позволяющая злоумышленнику вызвать отказ в обслуживании
BDU:2014-00148
Уязвимость браузера Google Chrome, позволяющая злоумышленнику вызвать отказ в обслуживании
BDU:2014-00151
Уязвимость браузера Google Chrome, позволяющая злоумышленнику вызвать отказ в обслуживании
BDU:2014-00155
Уязвимость браузера Google Chrome, позволяющая злоумышленнику внедрить произвольный веб-сценарий или HTML-код
BDU:2014-00157
Уязвимость браузера Google Chrome, позволяющая злоумышленнику вызвать отказ в обслуживании
BDU:2014-00182
Уязвимость браузера Google Chrome, позволяющая злоумышленнику вызвать отказ в обслуживании
BDU:2014-00195
Уязвимость браузера Google Chrome, позволяющая злоумышленнику подменить интерфейс пользователя
BDU:2014-00209
Уязвимость браузера Google Chrome, позволяющая злоумышленнику вызвать отказ в обслуживании
BDU:2014-00330
Уязвимость браузера Google Chrome, позволяющая злоумышленнику выполнить произвольный код или вызвать отказ в обслуживании
BDU:2014-00331
Уязвимость браузера Google Chrome, позволяющая злоумышленнику выполнить произвольный код или вызвать отказ в обслуживании
BDU:2014-00332
Уязвимость браузера Google Chrome, позволяющая злоумышленнику выполнить произвольный код или вызвать отказ в обслуживании
BDU:2015-00199
Уязвимости браузера Google Chrome, позволяющие удаленному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации
BDU:2015-00243
Уязвимость браузера Google Chrome, позволяющая удаленному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации
Modified: 2024-11-21
CVE-2014-1743
Use-after-free vulnerability in the StyleElement::removedFromDocument function in core/dom/StyleElement.cpp in Blink, as used in Google Chrome before 35.0.1916.114, allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via crafted JavaScript code that triggers tree mutation.
- http://googlechromereleases.blogspot.com/2014/05/stable-channel-update_20.html
- http://googlechromereleases.blogspot.com/2014/05/stable-channel-update_20.html
- openSUSE-SU-2014:0783
- openSUSE-SU-2014:0783
- 58920
- 58920
- 59155
- 59155
- 60372
- 60372
- GLSA-201408-16
- GLSA-201408-16
- DSA-2939
- DSA-2939
- 1030270
- 1030270
- https://code.google.com/p/chromium/issues/detail?id=356653
- https://code.google.com/p/chromium/issues/detail?id=356653
- https://src.chromium.org/viewvc/blink?revision=170702&view=revision
- https://src.chromium.org/viewvc/blink?revision=170702&view=revision
Modified: 2024-11-21
CVE-2014-1744
Integer overflow in the AudioInputRendererHost::OnCreateStream function in content/browser/renderer_host/media/audio_input_renderer_host.cc in Google Chrome before 35.0.1916.114 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger a large shared-memory allocation.
- http://googlechromereleases.blogspot.com/2014/05/stable-channel-update_20.html
- http://googlechromereleases.blogspot.com/2014/05/stable-channel-update_20.html
- openSUSE-SU-2014:0783
- openSUSE-SU-2014:0783
- 58920
- 58920
- 59155
- 59155
- 60372
- 60372
- GLSA-201408-16
- GLSA-201408-16
- DSA-2939
- DSA-2939
- 1030270
- 1030270
- https://code.google.com/p/chromium/issues/detail?id=359454
- https://code.google.com/p/chromium/issues/detail?id=359454
- https://src.chromium.org/viewvc/chrome?revision=261549&view=revision
- https://src.chromium.org/viewvc/chrome?revision=261549&view=revision
Modified: 2024-11-21
CVE-2014-1745
Use-after-free vulnerability in the SVG implementation in Blink, as used in Google Chrome before 35.0.1916.114, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger removal of an SVGFontFaceElement object, related to core/svg/SVGFontFaceElement.cpp.
- http://googlechromereleases.blogspot.com/2014/05/stable-channel-update_20.html
- http://googlechromereleases.blogspot.com/2014/05/stable-channel-update_20.html
- openSUSE-SU-2014:0783
- openSUSE-SU-2014:0783
- 58920
- 58920
- 59155
- 59155
- GLSA-201408-16
- GLSA-201408-16
- DSA-2939
- DSA-2939
- [oss-security] 20240206 WebKitGTK and WPE WebKit Security Advisory WSA-2024-0001
- [oss-security] 20240206 WebKitGTK and WPE WebKit Security Advisory WSA-2024-0001
- 1030270
- 1030270
- https://code.google.com/p/chromium/issues/detail?id=346192
- https://code.google.com/p/chromium/issues/detail?id=346192
- https://src.chromium.org/viewvc/blink?revision=167993&view=revision
- https://src.chromium.org/viewvc/blink?revision=167993&view=revision
Modified: 2024-11-21
CVE-2014-1746
The InMemoryUrlProtocol::Read function in media/filters/in_memory_url_protocol.cc in Google Chrome before 35.0.1916.114 relies on an insufficiently large integer data type, which allows remote attackers to cause a denial of service (out-of-bounds read) via vectors that trigger use of a large buffer.
- http://googlechromereleases.blogspot.com/2014/05/stable-channel-update_20.html
- http://googlechromereleases.blogspot.com/2014/05/stable-channel-update_20.html
- openSUSE-SU-2014:0783
- openSUSE-SU-2014:0783
- 58920
- 58920
- 59155
- 59155
- 60372
- 60372
- GLSA-201408-16
- GLSA-201408-16
- DSA-2939
- DSA-2939
- 1030270
- 1030270
- https://code.google.com/p/chromium/issues/detail?id=364065
- https://code.google.com/p/chromium/issues/detail?id=364065
- https://src.chromium.org/viewvc/chrome?revision=267280&view=revision
- https://src.chromium.org/viewvc/chrome?revision=267280&view=revision
Modified: 2024-11-21
CVE-2014-1747
Cross-site scripting (XSS) vulnerability in the DocumentLoader::maybeCreateArchive function in core/loader/DocumentLoader.cpp in Blink, as used in Google Chrome before 35.0.1916.114, allows remote attackers to inject arbitrary web script or HTML via crafted MHTML content, aka "Universal XSS (UXSS)."
- http://googlechromereleases.blogspot.com/2014/05/stable-channel-update_20.html
- http://googlechromereleases.blogspot.com/2014/05/stable-channel-update_20.html
- openSUSE-SU-2014:0783
- openSUSE-SU-2014:0783
- 58920
- 58920
- 59155
- 59155
- GLSA-201408-16
- GLSA-201408-16
- DSA-2939
- DSA-2939
- 1030270
- 1030270
- https://code.google.com/p/chromium/issues/detail?id=330663
- https://code.google.com/p/chromium/issues/detail?id=330663
- https://src.chromium.org/viewvc/blink?revision=169499&view=revision
- https://src.chromium.org/viewvc/blink?revision=169499&view=revision
Modified: 2024-11-21
CVE-2014-1748
The ScrollView::paint function in platform/scroll/ScrollView.cpp in Blink, as used in Google Chrome before 35.0.1916.114, allows remote attackers to spoof the UI by extending scrollbar painting into the parent frame.
- http://googlechromereleases.blogspot.com/2014/05/stable-channel-update_20.html
- http://googlechromereleases.blogspot.com/2014/05/stable-channel-update_20.html
- APPLE-SA-2014-12-2-1
- APPLE-SA-2014-12-2-1
- openSUSE-SU-2014:0783
- openSUSE-SU-2014:0783
- openSUSE-SU-2016:0915
- openSUSE-SU-2016:0915
- 58920
- 58920
- 59155
- 59155
- 60372
- 60372
- GLSA-201408-16
- GLSA-201408-16
- http://support.apple.com/kb/HT6596
- http://support.apple.com/kb/HT6596
- DSA-2939
- DSA-2939
- 1030270
- 1030270
- USN-2937-1
- USN-2937-1
- https://code.google.com/p/chromium/issues/detail?id=331168
- https://code.google.com/p/chromium/issues/detail?id=331168
- https://src.chromium.org/viewvc/blink?revision=170625&view=revision
- https://src.chromium.org/viewvc/blink?revision=170625&view=revision
Modified: 2024-11-21
CVE-2014-1749
Multiple unspecified vulnerabilities in Google Chrome before 35.0.1916.114 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
- http://googlechromereleases.blogspot.com/2014/05/stable-channel-update_20.html
- http://googlechromereleases.blogspot.com/2014/05/stable-channel-update_20.html
- openSUSE-SU-2014:0783
- openSUSE-SU-2014:0783
- 58920
- 58920
- 59155
- 59155
- GLSA-201408-16
- GLSA-201408-16
- DSA-2939
- DSA-2939
- 1030270
- 1030270
- https://code.google.com/p/chromium/issues/detail?id=374649
- https://code.google.com/p/chromium/issues/detail?id=374649
Modified: 2024-11-21
CVE-2014-3152
Integer underflow in the LCodeGen::PrepareKeyedOperand function in arm/lithium-codegen-arm.cc in Google V8 before 3.25.28.16, as used in Google Chrome before 35.0.1916.114, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger a negative key value.
- http://googlechromereleases.blogspot.com/2014/05/stable-channel-update_20.html
- http://googlechromereleases.blogspot.com/2014/05/stable-channel-update_20.html
- FEDORA-2015-6890
- FEDORA-2015-6890
- FEDORA-2015-6908
- FEDORA-2015-6908
- FEDORA-2015-6845
- FEDORA-2015-6845
- openSUSE-SU-2014:0783
- openSUSE-SU-2014:0783
- 58920
- 58920
- 59155
- 59155
- 60372
- 60372
- DSA-2939
- DSA-2939
- 1030270
- 1030270
- https://code.google.com/p/chromium/issues/detail?id=358057
- https://code.google.com/p/chromium/issues/detail?id=358057
- https://code.google.com/p/v8/source/detail?r=20363
- https://code.google.com/p/v8/source/detail?r=20363
Modified: 2024-11-21
CVE-2014-3154
Use-after-free vulnerability in the ChildThread::Shutdown function in content/child/child_thread.cc in the filesystem API in Google Chrome before 35.0.1916.153 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to a Blink shutdown.
- http://googlechromereleases.blogspot.com/2014/06/stable-channel-update.html
- http://googlechromereleases.blogspot.com/2014/06/stable-channel-update.html
- 58585
- 58585
- 59090
- 59090
- 60061
- 60061
- 60372
- 60372
- GLSA-201408-16
- GLSA-201408-16
- DSA-2959
- DSA-2959
- 67977
- 67977
- https://code.google.com/p/chromium/issues/detail?id=369525
- https://code.google.com/p/chromium/issues/detail?id=369525
- https://src.chromium.org/viewvc/blink?revision=173620&view=revision
- https://src.chromium.org/viewvc/blink?revision=173620&view=revision
- https://src.chromium.org/viewvc/chrome?revision=269345&view=revision
- https://src.chromium.org/viewvc/chrome?revision=269345&view=revision
Modified: 2024-11-21
CVE-2014-3155
net/spdy/spdy_write_queue.cc in the SPDY implementation in Google Chrome before 35.0.1916.153 allows remote attackers to cause a denial of service (out-of-bounds read) by leveraging incorrect queue maintenance.
- http://googlechromereleases.blogspot.com/2014/06/stable-channel-update.html
- http://googlechromereleases.blogspot.com/2014/06/stable-channel-update.html
- 58585
- 58585
- 59090
- 59090
- 60061
- 60061
- 60372
- 60372
- GLSA-201408-16
- GLSA-201408-16
- DSA-2959
- DSA-2959
- 67980
- 67980
- https://code.google.com/p/chromium/issues/detail?id=369539
- https://code.google.com/p/chromium/issues/detail?id=369539
- https://src.chromium.org/viewvc/chrome?revision=267984&view=revision
- https://src.chromium.org/viewvc/chrome?revision=267984&view=revision
- https://src.chromium.org/viewvc/chrome?revision=268730&view=revision
- https://src.chromium.org/viewvc/chrome?revision=268730&view=revision
- https://src.chromium.org/viewvc/chrome?revision=269246&view=revision
- https://src.chromium.org/viewvc/chrome?revision=269246&view=revision
Modified: 2024-11-21
CVE-2014-3156
Buffer overflow in the clipboard implementation in Google Chrome before 35.0.1916.153 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger unexpected bitmap data, related to content/renderer/renderer_clipboard_client.cc and content/renderer/webclipboard_impl.cc.
- http://googlechromereleases.blogspot.com/2014/06/stable-channel-update.html
- http://googlechromereleases.blogspot.com/2014/06/stable-channel-update.html
- 58585
- 58585
- 59090
- 59090
- 60061
- 60061
- GLSA-201408-16
- GLSA-201408-16
- DSA-2959
- DSA-2959
- 67981
- 67981
- https://code.google.com/p/chromium/issues/detail?id=369621
- https://code.google.com/p/chromium/issues/detail?id=369621
- https://src.chromium.org/viewvc/chrome?revision=271730&view=revision
- https://src.chromium.org/viewvc/chrome?revision=271730&view=revision
Modified: 2024-11-21
CVE-2014-3157
Heap-based buffer overflow in the FFmpegVideoDecoder::GetVideoBuffer function in media/filters/ffmpeg_video_decoder.cc in Google Chrome before 35.0.1916.153 allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging VideoFrame data structures that are too small for proper interaction with an underlying FFmpeg library.
- http://googlechromereleases.blogspot.com/2014/06/stable-channel-update.html
- http://googlechromereleases.blogspot.com/2014/06/stable-channel-update.html
- 58585
- 58585
- 59090
- 59090
- 60061
- 60061
- 60372
- 60372
- GLSA-201408-16
- GLSA-201408-16
- DSA-2959
- DSA-2959
- 67972
- 67972
- https://code.google.com/p/chromium/issues/detail?id=368980
- https://code.google.com/p/chromium/issues/detail?id=368980
- https://src.chromium.org/viewvc/chrome?revision=268831&view=revision
- https://src.chromium.org/viewvc/chrome?revision=268831&view=revision
Modified: 2024-11-21
CVE-2014-3160
The ResourceFetcher::canRequest function in core/fetch/ResourceFetcher.cpp in Blink, as used in Google Chrome before 36.0.1985.125, does not properly restrict subresource requests associated with SVG files, which allows remote attackers to bypass the Same Origin Policy via a crafted file.
- http://googlechromereleases.blogspot.com/2014/07/stable-channel-update.html
- http://googlechromereleases.blogspot.com/2014/07/stable-channel-update.html
- 60061
- 60061
- 60372
- 60372
- GLSA-201408-16
- GLSA-201408-16
- DSA-3039
- DSA-3039
- 68677
- 68677
- https://code.google.com/p/chromium/issues/detail?id=380885
- https://code.google.com/p/chromium/issues/detail?id=380885
- https://src.chromium.org/viewvc/blink?revision=176084&view=revision
- https://src.chromium.org/viewvc/blink?revision=176084&view=revision
Modified: 2024-11-21
CVE-2014-3803
The SpeechInput feature in Blink, as used in Google Chrome before 35.0.1916.114, allows remote attackers to enable microphone access and obtain speech-recognition text without indication via an INPUT element with a -x-webkit-speech attribute.
- http://blog.guya.net/2014/04/07/to-listen-without-consent-abusing-the-html5-speech/
- http://blog.guya.net/2014/04/07/to-listen-without-consent-abusing-the-html5-speech/
- http://googlechromereleases.blogspot.com/2014/05/stable-channel-update_20.html
- http://googlechromereleases.blogspot.com/2014/05/stable-channel-update_20.html
- 60372
- 60372
- 67582
- 67582
- https://code.google.com/p/chromium/issues/detail?id=360448
- https://code.google.com/p/chromium/issues/detail?id=360448
- https://src.chromium.org/viewvc/blink?revision=171373&view=revision
- https://src.chromium.org/viewvc/blink?revision=171373&view=revision
Closed bugs
Не верный перевод в chromium