---
title: "CVE-2014-7939\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2014-7939?format=md
keywords: index, follow
---

# CVE-2014-7939

Publication date 22 January 2015

Last updated 24 July 2024

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

Google Chrome before 40.0.2214.91, when the Harmony proxy in Google V8 is
enabled, allows remote attackers to bypass the Same Origin Policy via
crafted JavaScript code with Proxy.create and console.log calls, related to
HTTP responses that lack an "X-Content-Type-Options: nosniff" header.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2014-7939?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| chromium-browser | 15.10 wily | Fixed 40.0.2214.94-0ubuntu1.1120 |
| 15.04 vivid | Fixed 40.0.2214.94-0ubuntu1.1120 |
| 14.10 utopic | Fixed 40.0.2214.94-0ubuntu0.14.10.1.1110 |
| 14.04 LTS trusty | Fixed 40.0.2214.94-0ubuntu0.14.04.1.1068 |
| 12.04 LTS precise | Ignored |
| 10.04 LTS lucid | Ignored end of life |
| oxide-qt | 15.10 wily | Not affected |
| 15.04 vivid | Not affected |
| 14.10 utopic | Not affected |
| 14.04 LTS trusty | Not in release |
| 12.04 LTS precise | Not in release |
| 10.04 LTS lucid | Not in release |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Notes

---

### [chrisccoulson](https://launchpad.net/~chrisccoulson)

Harmony features are disabled in Oxide and there is no
mechanism to enable them

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-7939)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2014-7939)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2014-7939)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2014-7939)

### Other references

* <https://code.google.com/p/chromium/issues/detail?id=399951>
* <http://googlechromereleases.blogspot.com/2015/01/stable-update.html>
* <https://www.cve.org/CVERecord?id=CVE-2014-7939>
