First published: Wed Oct 08 2014(Updated: )
The wrap function in bindings/core/v8/custom/V8EventCustom.cpp in the V8 bindings in Blink, as used in Google Chrome before 38.0.2125.101, has an erroneous fallback outcome for wrapper-selection failures, which allows remote attackers to cause a denial of service via vectors that trigger stopping a worker process that had been handling an Event object.
Credit: cve-coordination@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat Enterprise Linux Desktop | =6.0 | |
Red Hat Enterprise Linux Server Supplementary | =6.0 | |
Red Hat Enterprise Linux Server Supplementary EUS | =6.6.z | |
Red Hat Enterprise Linux Workstation Supplementary | =6.0 | |
Google Chrome (Trace Event) | <=38.0.2125.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-3199 is classified as a moderate severity vulnerability due to its potential to cause denial of service.
CVE-2014-3199 affects Google Chrome versions up to 38.0.2125.7 and specific Red Hat Enterprise Linux versions including 6.0 and 6.6.z.
To fix CVE-2014-3199, update Google Chrome to a version higher than 38.0.2125.7 or apply the relevant patches provided by Red Hat for affected systems.
While CVE-2014-3199 was addressed in updates released in 2014, users on outdated versions may still be at risk.
CVE-2014-3199 can be exploited by remote attackers to trigger a denial of service condition in affected versions of Google Chrome.