First published: Wed Oct 08 2014(Updated: )
The SessionService::GetLastSession function in browser/sessions/session_service.cc in Google Chrome before 38.0.2125.101 allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via vectors that leverage "type confusion" for callback processing.
Credit: cve-coordination@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat enterprise linux desktop supplementary | =6.0 | |
Red Hat Enterprise Linux Server Supplementary | =6.0 | |
Red Hat Enterprise Linux Server Supplementary EUS | =6.6.z | |
Red Hat Enterprise Linux Workstation Supplementary | =6.0 | |
Google Chrome | <=38.0.2125.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-3193 has a severity rating that indicates it can lead to denial of service due to a use-after-free vulnerability.
To fix CVE-2014-3193, update Google Chrome to a version later than 38.0.2125.101 or apply the relevant Red Hat updates.
CVE-2014-3193 affects Google Chrome versions up to 38.0.2125.7 and specific versions of Red Hat Enterprise Linux 6.0 and 6.6.z.
CVE-2014-3193 is a use-after-free vulnerability that can be exploited via type confusion in callback processing.
Yes, CVE-2014-3193 may allow remote attackers to have unspecified other impacts in addition to denial of service.