Use-after-free vulnerability in the StyleElement::removedFromDocument function in core/dom/StyleElement.cpp in Blink, as used in Google Chrome before 35.0.1916.114, allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via crafted JavaScript code that triggers tree mutation.
Weaknesses in this category are related to improper management of system resources.
Link | Tags |
---|---|
http://www.debian.org/security/2014/dsa-2939 | vendor advisory |
http://googlechromereleases.blogspot.com/2014/05/stable-channel-update_20.html | |
http://security.gentoo.org/glsa/glsa-201408-16.xml | vendor advisory |
http://secunia.com/advisories/60372 | third party advisory |
http://lists.opensuse.org/opensuse-updates/2014-06/msg00023.html | vendor advisory |
http://secunia.com/advisories/59155 | third party advisory |
https://code.google.com/p/chromium/issues/detail?id=356653 | |
http://secunia.com/advisories/58920 | third party advisory |
https://src.chromium.org/viewvc/blink?revision=170702&view=revision | |
http://www.securitytracker.com/id/1030270 | vdb entry |