CVE-2014-1733CVE-2014-1733

Affected configuration(s):

cpe:/a:google:chrome:34.0.1847.130
cpe:/a:google:chrome:34.0.1847.131

Date published: 2014-04-26T06:55:05.543-04:00

Date last modified: 2017-01-06T21:59:43.330-05:00

CVSS Score: 7.5

Principal attack vector: NETWORK

Complexity:  LOW

Reference URL: http://googlechromereleases.blogspot.com/2014/04/stable-channel-update_24.html

Summary: The PointerCompare function in codegen.cc in Seccomp-BPF, as used in Google Chrome before 34.0.1847.131 on Windows and OS X and before 34.0.1847.132 on Linux, does not properly merge blocks, which might allow remote attackers to bypass intended sandbox restrictions by leveraging renderer access.

CategoriesUncategorised

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.