UBUNTU-CVE-2014-3172

Source
https://ubuntu.com/security/CVE-2014-3172
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2014/UBUNTU-CVE-2014-3172.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2014-3172
Upstream
  • CVE-2014-3172
Published
2014-08-27T01:55:00Z
Modified
2025-09-08T16:43:09Z
Severity
  • Ubuntu - medium
Summary
[none]
Details

The Debugger extension API in browser/extensions/api/debugger/debugger_api.cc in Google Chrome before 37.0.2062.94 does not validate a tab's URL before an attach operation, which allows remote attackers to bypass intended access limitations via an extension that uses a restricted URL, as demonstrated by a chrome:// URL.

References

Affected packages

Ubuntu:14.04:LTS / chromium-browser

Package

Name
chromium-browser
Purl
pkg:deb/ubuntu/chromium-browser@37.0.2062.94-0ubuntu0.14.04.1~pkg1042?arch=source&distro=trusty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
37.0.2062.94-0ubuntu0.14.04.1~pkg1042

Affected versions

29.*
29.0.1547.65-0ubuntu2
31.*
31.0.1650.63-0ubuntu1~20131204.1
32.*
32.0.1700.107-0ubuntu1~20140204.977.1
33.*
33.0.1750.152-0ubuntu1~pkg995.1
34.*
34.0.1847.116-0ubuntu2
36.*
36.0.1985.125-0ubuntu1.14.04.0~pkg1029

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "chromium-browser",
            "binary_version": "37.0.2062.94-0ubuntu0.14.04.1~pkg1042"
        },
        {
            "binary_name": "chromium-browser-l10n",
            "binary_version": "37.0.2062.94-0ubuntu0.14.04.1~pkg1042"
        },
        {
            "binary_name": "chromium-chromedriver",
            "binary_version": "37.0.2062.94-0ubuntu0.14.04.1~pkg1042"
        },
        {
            "binary_name": "chromium-codecs-ffmpeg",
            "binary_version": "37.0.2062.94-0ubuntu0.14.04.1~pkg1042"
        },
        {
            "binary_name": "chromium-codecs-ffmpeg-extra",
            "binary_version": "37.0.2062.94-0ubuntu0.14.04.1~pkg1042"
        }
    ],
    "availability": "No subscription required"
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2014/UBUNTU-CVE-2014-3172.json"