FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2013-6638

This CVE name corresponds to:

Entered Topic
2013-12-05 chromium -- multiple vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2013-6638
Phase Assigned(20131105)

Description

Multiple buffer overflows in runtime.cc in Google V8 before 3.22.24.7, as used in Google Chrome before 31.0.1650.63, allow remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger a large typed array, related to the (1) Runtime_TypedArrayInitialize and (2) Runtime_TypedArrayInitializeFromArrayLike functions.

References

Source Reference
MLIST [v8-dev] 20131115 Limit the size for typed arrays to MaxSmi. (issue 73943004)
CONFIRM http://code.google.com/p/v8/source/detail?r=17800
CONFIRM http://googlechromereleases.blogspot.com/2013/12/stable-channel-update.html
CONFIRM https://code.google.com/p/chromium/issues/detail?id=319722
DEBIAN DSA-2811
SUSE openSUSE-SU-2013:1927
SUSE openSUSE-SU-2013:1933
SUSE openSUSE-SU-2013:1960
SUSE openSUSE-SU-2013:1962
SUSE openSUSE-SU-2014:0092
SUSE openSUSE-SU-2014:0065
SECTRACK 1029442
SECUNIA 56216
SECUNIA 56217