CVE-2014-1730

NameCVE-2014-1730
DescriptionGoogle V8, as used in Google Chrome before 34.0.1847.131 on Windows and OS X and before 34.0.1847.132 on Linux, does not properly store internationalization metadata, which allows remote attackers to bypass intended access restrictions by leveraging "type confusion" and reading property values, related to i18n.js and runtime.cc.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDSA-2920-1
Debian Bugs773671

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
chromium-browser (PTS)jessie, jessie (lts)57.0.2987.98-1~deb8u1fixed
stretch (security), stretch (lts), stretch71.0.3578.80-1~deb9u1fixed
libv8-3.14 (PTS)jessie3.14.5.8-8.1vulnerable
stretch3.14.5.8-11vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
chromium-browsersourcesqueeze(unfixed)end-of-life
chromium-browsersourcewheezy34.0.1847.132-1~deb7u1DSA-2920-1
chromium-browsersource(unstable)34.0.1847.132-1
libv8sourcesqueeze(unfixed)end-of-life
libv8source(unstable)(unfixed)
libv8-3.14source(unstable)(unfixed)unimportant773671

Notes

[wheezy] - libv8 <no-dsa> (Minor issue, Chromium in Wheezy uses its own fixed copy)
[squeeze] - libv8 <end-of-life> (Unsupported in squeeze-lts)
libv8 not covered by security support

Search for package or bug name: Reporting problems