FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2014-3174

This CVE name corresponds to:

Entered Topic
2014-08-26 chromium -- multiple vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2014-3174
Phase Assigned(20140503)

Description

modules/webaudio/BiquadDSPKernel.cpp in the Web Audio API implementation in Blink, as used in Google Chrome before 37.0.2062.94, does not properly consider concurrent threads during attempts to update biquad filter coefficients, which allows remote attackers to cause a denial of service (read of uninitialized memory) via crafted API calls.

References

Source Reference
CONFIRM http://googlechromereleases.blogspot.com/2014/08/stable-channel-update_26.html
CONFIRM https://crbug.com/389219
CONFIRM https://src.chromium.org/viewvc/blink?revision=177250&view=revision
DEBIAN DSA-3039
SUSE openSUSE-SU-2014:1151
SECTRACK 1030767