PT-2014-1180 · Google+9 · Google Chrome+9
Publicado
2014-05-20
·
Atualizado
2025-06-04
·
CVE-2014-1745
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Google Chrome versions prior to 35.0.1916.114
Description
The issue is related to a use-after-free vulnerability in the SVG implementation in Blink, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger removal of an
SVGFontFaceElement object. This is related to the core/svg/SVGFontFaceElement.cpp file. The estimated number of potentially affected devices worldwide is not specified. There is no information about real-world incidents where this issue was exploited.Recommendations
For Google Chrome versions prior to 35.0.1916.114, update to version 35.0.1916.114 or later to resolve the issue. As a temporary workaround, consider disabling the use of
SVGFontFaceElement objects until a patch is available. Restrict access to the vulnerable SVG implementation to minimize the risk of exploitation. Avoid using vectors that trigger removal of an SVGFontFaceElement object in the affected API endpoints until the issue is resolved.Exploit
Correção
DoS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Almalinux
Astra Linux
Centos
Debian
Google Chrome
Apple Macos
Red Hat
Rocky Linux
Suse