MGASA-2014-0485

Source
https://advisories.mageia.org/MGASA-2014-0485.html
Import Source
https://advisories.mageia.org/MGASA-2014-0485.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2014-0485
Upstream
  • CVE-2014-7904
  • CVE-2014-7906
  • CVE-2014-7907
  • CVE-2014-7908
  • CVE-2014-7909
  • CVE-2014-7910
Published
2014-11-25T09:21:26Z
Modified
2026-04-16T06:25:22.274993450Z
Summary
Updated chromium-browser-stable fixes multiple security vulnerabilities
Details

Updated chromium-browser-stable packages fix security vulnerabilities:

Buffer overflow in Skia, as used in Google Chrome before 39.0.2171.65, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors (CVE-2014-7904).

Use-after-free vulnerability in the Pepper plugins in Google Chrome before 39.0.2171.65 allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted Flash content that triggers an attempted PepperMediaDeviceManager access outside of the object's lifetime (CVE-2014-7906).

Multiple use-after-free vulnerabilities in modules/screen_orientation/ScreenOrientationController.cpp in Blink, as used in Google Chrome before 39.0.2171.65, allow remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger improper handling of a detached frame, related to the lock and unlock methods (CVE-2014-7907).

Multiple integer overflows in the CheckMov function in media/base/container_names.cc in Google Chrome before 39.0.2171.65 allow remote attackers to cause a denial of service or possibly have unspecified other impact via a large atom in MPEG-4 or QuickTime .mov data (CVE-2014-7908).

effects/SkDashPathEffect.cpp in Skia, as used in Google Chrome before 39.0.2171.65, computes a hash key using uninitialized integer values, which might allow remote attackers to cause a denial of service by rendering crafted data (CVE-2014-7909).

Multiple unspecified vulnerabilities in Google Chrome before 39.0.2171.65 allow attackers to cause a denial of service or possibly have other impact via unknown vectors (CVE-2014-7910).

References
Credits

Affected packages

Mageia:3 / chromium-browser-stable

Package

Name
chromium-browser-stable
Purl
pkg:rpm/mageia/chromium-browser-stable?arch=source&distro=mageia-3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
39.0.2171.65-1.mga3

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2014-0485.json"

Mageia:3 / chromium-browser-stable

Package

Name
chromium-browser-stable
Purl
pkg:rpm/mageia/chromium-browser-stable?arch=source&distro=mageia-3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
39.0.2171.65-1.mga3.tainted

Ecosystem specific

{
    "section": "tainted"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2014-0485.json"

Mageia:4 / chromium-browser-stable

Package

Name
chromium-browser-stable
Purl
pkg:rpm/mageia/chromium-browser-stable?arch=source&distro=mageia-4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
39.0.2171.65-1.mga4

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2014-0485.json"