First published: Thu Jan 22 2015(Updated: )
The Fonts implementation in Google Chrome before 40.0.2214.91 does not initialize memory for a data structure, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
Credit: cve-coordination@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
Chromium | =40.0.2214.110 | |
Red Hat Enterprise Linux Desktop | =6.0 | |
Red Hat Enterprise Linux Server Supplementary | =6.0 | |
Red Hat Enterprise Linux Server Supplementary EUS | =6.6.z | |
Red Hat Enterprise Linux Workstation Supplementary | =6.0 | |
Google Chrome (Trace Event) | <=40.0.2214.85 | |
SUSE Linux | =13.1 | |
SUSE Linux | =13.2 | |
Ubuntu | =14.04 | |
Ubuntu | =14.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-7942 has a severity rating that allows remote attackers to cause a denial of service.
To fix CVE-2014-7942, update Google Chrome or the affected operating system to the latest version where the vulnerability has been patched.
CVE-2014-7942 affects Chrome versions prior to 40.0.2214.91 and multiple versions of Red Hat Enterprise Linux, Ubuntu, and openSUSE.
Yes, CVE-2014-7942 can be exploited by remote attackers to trigger a denial of service.
CVE-2014-7942 can lead to denial of service or potentially other unspecified impacts.