CVE-2014-7940: High severity google chrome (trace event) vulnerability
The collator implementation in i18n/ucol.cpp in International Components for Unicode (ICU) 52 through SVN revision 293126, as used in Google Chrome before 40.0.2214.91, does not initialize memory for a data structure, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted character sequence.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2014-7940?
CVE-2014-7940 is classified as a medium severity vulnerability.
How do I fix CVE-2014-7940?
To fix CVE-2014-7940, update Google Chrome to version 40.0.2214.91 or later.
What are the potential impacts of CVE-2014-7940?
CVE-2014-7940 can lead to denial of service and may allow remote attackers to exploit uninitialized memory.
Which software versions are affected by CVE-2014-7940?
CVE-2014-7940 affects Google Chrome versions before 40.0.2214.91 and ICU versions up to 52.1.
Is CVE-2014-7940 exploitable by remote attackers?
Yes, CVE-2014-7940 can be exploited by remote attackers to impact system stability.