CVE-2014-3194: Use After Free
Published Oct 8, 2014
·Updated
Use-after-free vulnerability in the Web Workers implementation in Google Chrome before 38.0.2125.101 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
Affected Software
5 affected components
redhat Enterprise Linux Desktop Supplementary=6.0
redhat Enterprise Linux Server Supplementary=6.0
redhat Enterprise Linux Server Supplementary Eus=6.6.z
redhat Enterprise Linux Workstation Supplementary=6.0
Google Chrome<=38.0.2125.7
Remediation
Patch Available
Event History
Oct 8, 2014
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-3194?
The severity of CVE-2014-3194 is high due to the potential for denial of service and other unspecified impacts.
2
How do I fix CVE-2014-3194?
To fix CVE-2014-3194, update Google Chrome to version 38.0.2125.101 or later.
3
Which versions of Google Chrome are affected by CVE-2014-3194?
CVE-2014-3194 affects Google Chrome versions prior to 38.0.2125.101.
4
What type of vulnerability is CVE-2014-3194?
CVE-2014-3194 is a use-after-free vulnerability specifically in the Web Workers implementation.
5
Can CVE-2014-3194 be exploited remotely?
Yes, CVE-2014-3194 allows remote attackers to exploit the vulnerability via unknown vectors.