CVE-2014-1706: High severity Google Chrome OS vulnerability
Published Mar 16, 2014
·Updated
crosh in Google Chrome OS before 33.0.1750.152 allows attackers to inject commands via unspecified vectors.
Affected Software
11 affected components
Google Chrome OS<=33.0.1750.149
Google Chrome OS=33.0.1750.2
Google Chrome OS=33.0.1750.5
Google Chrome OS=33.0.1750.16
Google Chrome OS=33.0.1750.29
Google Chrome OS=33.0.1750.51
Google Chrome OS=33.0.1750.58
Google Chrome OS=33.0.1750.70
Google Chrome OS=33.0.1750.93
Google Chrome OS=33.0.1750.112
Google Chrome OS=33.0.1750.124
Event History
Mar 16, 2014
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Data Sourced
via NVD·02:06 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-1706?
CVE-2014-1706 is categorized as a high severity vulnerability due to its potential to allow command injection.
2
How do I fix CVE-2014-1706?
To fix CVE-2014-1706, users should update their Google Chrome OS to the latest version beyond 33.0.1750.152.
3
What systems are affected by CVE-2014-1706?
CVE-2014-1706 affects Google Chrome OS versions prior to 33.0.1750.152.
4
Can CVE-2014-1706 lead to remote code execution?
Yes, CVE-2014-1706 can potentially allow remote attackers to execute arbitrary commands.
5
Is there a workaround for CVE-2014-1706?
There are no recommended workarounds for CVE-2014-1706; updating the software is the best mitigation.