RULE(RULE ID:310985)

Rule General Information
Release Date: 2020-06-02
Rule Name: Google Chrome locationAttributeSetter Use After Free Vulnerability (CVE-2014-1713)
Severity:
CVE ID:
Rule Protection Details
Description: Use-after-free vulnerability in the AttributeSetter function in bindings/templates/attributes.cpp in the bindings in Blink, as used in Google Chrome before 33.0.1750.152 on OS X and Linux and before 33.0.1750.154 on Windows, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving the document.location value.
Impact: A use-after-free vulnerability can be exploited by an attacker in the vulnerable product. Successful exploit may cause some adverse consequences, such as crash of the product, execution of arbitrary code.
Affected OS: Windows
Reference: http://archives.neohapsis.com/archives/bugtraq/2014-03/0144.html
http://archives.neohapsis.com/archives/bugtraq/2014-04/0009.html
http://archives.neohapsis.com/archives/bugtraq/2014-04/0135.html
http://archives.neohapsis.com/archives/bugtraq/2014-04/0136.html
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
http://googlechromereleases.blogspot.com/2014/03/stable-channel-update_14.html