CVE-2014-3193: Use After Free
The SessionService::GetLastSession function in browser/sessions/sessionservice.cc in Google Chrome before 38.0.2125.101 allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via vectors that leverage "type confusion" for callback processing.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3193?
CVE-2014-3193 has a severity rating that indicates it can lead to denial of service due to a use-after-free vulnerability.
How do I fix CVE-2014-3193?
To fix CVE-2014-3193, update Google Chrome to a version later than 38.0.2125.101 or apply the relevant Red Hat updates.
Which versions of software are affected by CVE-2014-3193?
CVE-2014-3193 affects Google Chrome versions up to 38.0.2125.7 and specific versions of Red Hat Enterprise Linux 6.0 and 6.6.z.
What type of vulnerability is CVE-2014-3193?
CVE-2014-3193 is a use-after-free vulnerability that can be exploited via type confusion in callback processing.
Can CVE-2014-3193 lead to other impacts apart from denial of service?
Yes, CVE-2014-3193 may allow remote attackers to have unspecified other impacts in addition to denial of service.