CVE-2014-1733
The PointerCompare function in codegen.cc in Seccomp-BPF, as used in Google Chrome before 34.0.1847.131 on Windows and OS X and before 34.0.1847.132 on Linux, does not properly merge blocks, which might allow remote attackers to bypass intended sandbox…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.67%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The PointerCompare function in codegen.cc in Seccomp-BPF, as used in Google Chrome before 34.0.1847.131 on Windows and OS X and before 34.0.1847.132 on Linux, does not properly merge blocks, which might allow remote attackers to bypass intended sandbox restrictions by leveraging renderer access.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.67% probability · 76th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- google/chrome
- Source
- chrome-cve-admin@google.com
References
- http://googlechromereleases.blogspot.com/2014/04/stable-channel-update_24.html
- http://lists.opensuse.org/opensuse-updates/2014-05/msg00049.html
- http://lists.opensuse.org/opensuse-updates/2014-05/msg00050.html
- http://secunia.com/advisories/58301
- http://security.gentoo.org/glsa/glsa-201408-16.xml
- http://www.debian.org/security/2014/dsa-2920
- https://code.google.com/p/chromium/issues/detail?id=351103
- https://src.chromium.org/viewvc/chrome?revision=260157&view=revision
- http://googlechromereleases.blogspot.com/2014/04/stable-channel-update_24.html
- http://lists.opensuse.org/opensuse-updates/2014-05/msg00049.html
- http://lists.opensuse.org/opensuse-updates/2014-05/msg00050.html
- http://secunia.com/advisories/58301
- http://security.gentoo.org/glsa/glsa-201408-16.xml
- http://www.debian.org/security/2014/dsa-2920
- https://code.google.com/p/chromium/issues/detail?id=351103
- https://src.chromium.org/viewvc/chrome?revision=260157&view=revision
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.