Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges

Alerts This Week
Warning Icon 1 488
Alerts This Week
Warning Icon 1 488

Debian Wheezy DSA-2905-1 Critical: Chromium Browser Security Issues

debian
Calendar Grey April 16, 2014
Scroller Debian
Uncover vulnerabilities within the chromium-browser and receive update instructions. Critical patches for Debian users.
Several vulnerabilities were discovered in the chromium web browser

Summary

CVE-2014-1716

A cross-site scripting issue was discovered in the v8 javascript
library.

CVE-2014-1717

An out-of-bounds read issue was discovered in the v8 javascript
library.

CVE-2014-1718

Aaron Staple discovered an integer overflow issue in chromium's
software compositor.

CVE-2014-1719

Colin Payne discovered a use-after-free issue in the web workers implementation.

CVE-2014-1720

cloudfuzzer discovered a use-after-free issue in the Blink/Webkit
document object model implementation.

CVE-2014-1721

Christian Holler discovered a memory corruption issue in the v8
javascript library.

CVE-2014-1722

miaubiz discovered a use-after-free issue in block rendering.

CVE-2014-1723

George McBay discovered a url spoofing issue.

CVE-2014-1724

Atte Kettunen discovered a use-after-free issue in freebsoft's
libspeechd library.

Because of this issue, the text-to-speech feature is now disabled
by default ("--enable-speech-dispatcher" at the command-line can
...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: chromium-browser
CVE ID: CVE-2014-1716 CVE-2014-1717 CVE-2014-1718 CVE-2014-1719

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.