CVE-2014-7923
Publication date 22 January 2015
Last updated 24 July 2024
Ubuntu priority
The Regular Expressions package in International Components for Unicode (ICU) 52 before SVN revision 292944, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via vectors related to a look-behind expression.
Status
Package | Ubuntu Release | Status |
---|---|---|
chromium-browser | ||
14.04 LTS trusty |
Fixed 40.0.2214.94-0ubuntu0.14.04.1.1068
|
|
icu | ||
14.04 LTS trusty |
Fixed 52.1-3ubuntu0.2
|
|
oxide-qt | ||
14.04 LTS trusty |
Fixed 1.4.2-0ubuntu0.14.04.1
|
|
References
Related Ubuntu Security Notices (USN)
- USN-2522-1
- ICU vulnerabilities
- 5 March 2015
- USN-2476-1
- Oxide vulnerabilities
- 26 January 2015
Other references
- https://codereview.chromium.org/726973003
- https://chromium.googlesource.com/chromium/deps/icu52/+/6242e2fbb36f486f2c0addd1c3cef67fc4ed33fb
- https://chromium.googlesource.com/chromium/deps/icu52/+/3af4ce5982311035e5f36803d547c0befa576c8c
- http://googlechromereleases.blogspot.com/2015/01/stable-update.html
- https://www.cve.org/CVERecord?id=CVE-2014-7923