CVE-2014-1701

Publication date 16 March 2014

Last updated 24 July 2024


Ubuntu priority

The GenerateFunction function in bindings/scripts/code_generator_v8.pm in Blink, as used in Google Chrome before 33.0.1750.149, does not implement a certain cross-origin restriction for the EventTarget::dispatchEvent function, which allows remote attackers to conduct Universal XSS (UXSS) attacks via vectors involving events.

Status

No maintained releases are affected by this CVE.

Package Ubuntu Release Status
chromium-browser 13.10 saucy
Fixed 33.0.1750.152-0ubuntu0.13.10.1~pkg984.1
12.10 quantal
Fixed 33.0.1750.152-0ubuntu0.12.10.1~pkg895.1
12.04 LTS precise
Fixed 33.0.1750.152-0ubuntu0.12.04.1~pkg879.1
10.04 LTS lucid Ignored end of life
oxide-qt 13.10 saucy Not in release
12.10 quantal Not in release
12.04 LTS precise Not in release
10.04 LTS lucid Not in release