CVE-2014-7941
22.01.2015, 22:59
The SelectionOwner::ProcessTarget function in ui/base/x/selection_owner.cc in the UI implementation in Google Chrome before 40.0.2214.91 uses an incorrect data type for a certain length value, which allows remote attackers to cause a denial of service (out-of-bounds read) via crafted X11 data.Enginsight
Vendor | Product | Version |
---|---|---|
chromium | chromium | 40.0.2214.110 |
redhat | enterprise_linux_desktop_supplementary | 6.0 |
redhat | enterprise_linux_server_supplementary | 6.0 |
redhat | enterprise_linux_server_supplementary_eus | 6.6.z:z |
redhat | enterprise_linux_workstation_supplementary | 6.0 |
chrome | 𝑥 ≤ 40.0.2214.85 | |
opensuse | opensuse | 13.1 |
opensuse | opensuse | 13.2 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Ubuntu Product | |||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
chromium-browser |
| ||||||||||||
oxide-qt |
|
Common Weakness Enumeration
References