CVE-2014-3803
Publication date 21 May 2014
Last updated 24 July 2024
Ubuntu priority
The SpeechInput feature in Blink, as used in Google Chrome before 35.0.1916.114, allows remote attackers to enable microphone access and obtain speech-recognition text without indication via an INPUT element with a -x-webkit-speech attribute.
Status
Package | Ubuntu Release | Status |
---|---|---|
chromium-browser | 14.04 LTS trusty |
Fixed 36.0.1985.125-0ubuntu1.14.04.0~pkg1029
|
oxide-qt | 14.04 LTS trusty |
Fixed 1.0.4-0ubuntu0.14.04.1
|
References
Related Ubuntu Security Notices (USN)
- USN-2298-1
- Oxide vulnerabilities
- 23 July 2014
Other references
- https://src.chromium.org/viewvc/blink?revision=171373&view=revision
- https://code.google.com/p/chromium/issues/detail?id=360448
- http://googlechromereleases.blogspot.com/2014/05/stable-channel-update_20.html
- http://blog.guya.net/2014/04/07/to-listen-without-consent-abusing-the-html5-speech/
- https://www.cve.org/CVERecord?id=CVE-2014-3803