CVE-2014-7926
Publication date 22 January 2015
Last updated 24 July 2024
Ubuntu priority
The Regular Expressions package in International Components for Unicode (ICU) 52 before SVN revision 292944, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via vectors related to a zero-length quantifier.
Status
Package | Ubuntu Release | Status |
---|---|---|
chromium-browser | ||
14.04 LTS trusty |
Fixed 40.0.2214.94-0ubuntu0.14.04.1.1068
|
|
icu | ||
14.04 LTS trusty |
Fixed 52.1-3ubuntu0.2
|
|
oxide-qt | ||
14.04 LTS trusty |
Fixed 1.4.2-0ubuntu0.14.04.1
|
|
References
Related Ubuntu Security Notices (USN)
- USN-2522-1
- ICU vulnerabilities
- 5 March 2015
- USN-2476-1
- Oxide vulnerabilities
- 26 January 2015
Other references
- https://codereview.chromium.org/726973003
- https://chromium.googlesource.com/chromium/deps/icu52/+/6242e2fbb36f486f2c0addd1c3cef67fc4ed33fb
- https://chromium.googlesource.com/chromium/deps/icu52/+/3af4ce5982311035e5f36803d547c0befa576c8c
- http://googlechromereleases.blogspot.com/2015/01/stable-update.html
- https://www.cve.org/CVERecord?id=CVE-2014-7926