---
title: "CVE-2014-3177\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2014-3177?format=md
keywords: index, follow
---

# CVE-2014-3177

Publication date 27 August 2014

Last updated 24 July 2024

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

Google Chrome before 37.0.2062.94 does not properly handle the interaction
of extensions, IPC, the sync API, and Google V8, which allows remote
attackers to execute arbitrary code via unspecified vectors, a different
vulnerability than CVE-2014-3176.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| chromium-browser | 14.04 LTS trusty | Fixed 37.0.2062.94-0ubuntu0.14.04.1~pkg1042 |
| 12.04 LTS precise | Fixed 37.0.2062.94-0ubuntu0.12.04.1~pkg909 |
| 10.04 LTS lucid | Ignored end of life |
| oxide-qt | 14.04 LTS trusty | Not in release |
| 12.04 LTS precise | Not in release |
| 10.04 LTS lucid | Not in release |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3177)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2014-3177)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2014-3177)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2014-3177)

### Other references

* <https://crbug.com/386988>
* <http://googlechromereleases.blogspot.com/2014/08/stable-channel-update_26.html>
* <https://www.cve.org/CVERecord?id=CVE-2014-3177>
