CVE-2014-1346
Publication date 22 May 2014
Last updated 24 July 2024
Ubuntu priority
WebKit, as used in Apple Safari before 6.1.4 and 7.x before 7.0.4, does not properly interpret Unicode encoding, which allows remote attackers to spoof a postMessage origin, and bypass intended restrictions on sending a message to a connected frame or window, via crafted characters in a URL.
Status
Package | Ubuntu Release | Status |
---|---|---|
webkit | ||
16.04 LTS xenial | Not in release | |
14.04 LTS trusty | Not in release | |
qtwebkit-opensource-src | ||
16.04 LTS xenial | Ignored no update available | |
14.04 LTS trusty | Not in release | |
qtwebkit-source | ||
16.04 LTS xenial | Ignored no update available | |
14.04 LTS trusty | Not in release | |
webkitgtk | ||
16.04 LTS xenial |
Not affected
|
|
14.04 LTS trusty | Not in release | |