UBUNTU-CVE-2014-7899

Source
https://ubuntu.com/security/CVE-2014-7899
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2014/UBUNTU-CVE-2014-7899.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2014-7899
Upstream
  • CVE-2014-7899
Withdrawn
2025-07-18T16:43:05Z
Published
2014-11-19T11:59:00Z
Modified
2025-07-16T07:17:20.613427Z
Severity
  • Ubuntu - medium
Summary
[none]
Details

Google Chrome before 38.0.2125.101 allows remote attackers to spoof the address bar by placing a blob: substring at the beginning of the URL, followed by the original URI scheme and a long username string.

References

Affected packages

Ubuntu:14.04:LTS / chromium-browser

Package

Name
chromium-browser
Purl
pkg:deb/ubuntu/chromium-browser@38.0.2125.111-0ubuntu0.14.04.1.1061?arch=source&distro=trusty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
38.0.2125.111-0ubuntu0.14.04.1.1061

Affected versions

29.*
29.0.1547.65-0ubuntu2
31.*
31.0.1650.63-0ubuntu1~20131204.1
32.*
32.0.1700.107-0ubuntu1~20140204.977.1
33.*
33.0.1750.152-0ubuntu1~pkg995.1
34.*
34.0.1847.116-0ubuntu2
36.*
36.0.1985.125-0ubuntu1.14.04.0~pkg1029
37.*
37.0.2062.94-0ubuntu0.14.04.1~pkg1042
37.0.2062.120-0ubuntu0.14.04.1~pkg1049

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "chromium-browser",
            "binary_version": "38.0.2125.111-0ubuntu0.14.04.1.1061"
        },
        {
            "binary_name": "chromium-browser-dbg",
            "binary_version": "38.0.2125.111-0ubuntu0.14.04.1.1061"
        },
        {
            "binary_name": "chromium-browser-l10n",
            "binary_version": "38.0.2125.111-0ubuntu0.14.04.1.1061"
        },
        {
            "binary_name": "chromium-chromedriver",
            "binary_version": "38.0.2125.111-0ubuntu0.14.04.1.1061"
        },
        {
            "binary_name": "chromium-chromedriver-dbg",
            "binary_version": "38.0.2125.111-0ubuntu0.14.04.1.1061"
        },
        {
            "binary_name": "chromium-codecs-ffmpeg",
            "binary_version": "38.0.2125.111-0ubuntu0.14.04.1.1061"
        },
        {
            "binary_name": "chromium-codecs-ffmpeg-dbg",
            "binary_version": "38.0.2125.111-0ubuntu0.14.04.1.1061"
        },
        {
            "binary_name": "chromium-codecs-ffmpeg-extra",
            "binary_version": "38.0.2125.111-0ubuntu0.14.04.1.1061"
        },
        {
            "binary_name": "chromium-codecs-ffmpeg-extra-dbg",
            "binary_version": "38.0.2125.111-0ubuntu0.14.04.1.1061"
        }
    ],
    "availability": "No subscription required"
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2014/UBUNTU-CVE-2014-7899.json"