Vulnerability Name:

CVE-2014-3197 (CCN-96966)

Assigned:2014-10-07
Published:2014-10-07
Updated:2016-11-28
Summary:The NavigationScheduler::schedulePageBlock function in core/loader/NavigationScheduler.cpp in Blink, as used in Google Chrome before 38.0.2125.101, does not properly provide substitute data for pages blocked by the XSS auditor, which allows remote attackers to obtain sensitive information via a crafted web site.
CVSS v3 Severity:5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): None
Availibility (A): None
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
4.3 Medium (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N)
3.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
4.3 Medium (REDHAT CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N)
3.2 Low (REDHAT Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
Vulnerability Type:CWE-264
Vulnerability Consequences:Obtain Information
References:Source: MITRE
Type: CNA
CVE-2014-3197

Source: CCN
Type: Google Chrome Releases Web site
Stable Channel Update

Source: CONFIRM
Type: Vendor Advisory
http://googlechromereleases.blogspot.com/2014/10/stable-channel-update.html

Source: CCN
Type: RHSA-2014-1626
Critical: chromium-browser security update

Source: REDHAT
Type: Third Party Advisory
RHSA-2014:1626

Source: BID
Type: UNKNOWN
70273

Source: CCN
Type: BID-70273
Google Chrome Prior to 38.0.2125.101 Multiple Security Vulnerabilities

Source: CONFIRM
Type: UNKNOWN
https://crbug.com/396544

Source: XF
Type: UNKNOWN
google-chrome-cve20143197-info-disc(96966)

Source: CONFIRM
Type: UNKNOWN
https://src.chromium.org/viewvc/blink?revision=179240&view=revision

Vulnerable Configuration:Configuration 1:
  • cpe:/a:google:chrome:*:*:*:*:*:*:*:* (Version <= 38.0.2125.7)

  • Configuration 2:
  • cpe:/o:redhat:enterprise_linux_desktop_supplementary:6.0:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_server_supplementary:6.0:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_server_supplementary_eus:6.6.z:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_workstation_supplementary:6.0:*:*:*:*:*:*:*

  • Configuration RedHat 1:
  • cpe:/a:redhat:rhel_extras:6:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20143197
    V
    CVE-2014-3197
    2022-06-30
    oval:org.opensuse.security:def:112065
    P
    chromedriver-55.0.2883.75-3.1 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:105614
    P
    chromedriver-55.0.2883.75-3.1 on GA media (Moderate)
    2021-10-01
    oval:org.mitre.oval:def:27125
    P
    RHSA-2014:1626: chromium-browser security update (Critical)
    2014-11-24
    oval:org.mitre.oval:def:27038
    P
    USN-2345-1 -- Oxide vulnerabilities
    2014-11-24
    oval:com.redhat.rhsa:def:20141626
    P
    RHSA-2014:1626: chromium-browser security update (Critical)
    2014-10-14
    oval:com.ubuntu.precise:def:20143197000
    V
    CVE-2014-3197 on Ubuntu 12.04 LTS (precise) - medium.
    2014-10-08
    oval:com.ubuntu.trusty:def:20143197000
    V
    CVE-2014-3197 on Ubuntu 14.04 LTS (trusty) - medium.
    2014-10-08
    BACK
    google chrome *
    redhat enterprise linux desktop supplementary 6.0
    redhat enterprise linux server supplementary 6.0
    redhat enterprise linux server supplementary eus 6.6.z
    redhat enterprise linux workstation supplementary 6.0