Upstream information

CVE-2013-6638 at MITRE

Description

Multiple buffer overflows in runtime.cc in Google V8 before 3.22.24.7, as used in Google Chrome before 31.0.1650.63, allow remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger a large typed array, related to the (1) Runtime_TypedArrayInitialize and (2) Runtime_TypedArrayInitializeFromArrayLike functions.

SUSE information

Overall state of this security issue: Does not affect SUSE products

This issue is currently rated as having important severity.

CVSS v2 Scores
  National Vulnerability Database
Base Score 7.5
Vector AV:N/AC:L/Au:N/C:P/I:P/A:P
Access Vector Network
Access Complexity Low
Authentication None
Confidentiality Impact Partial
Integrity Impact Partial
Availability Impact Partial
SUSE Bugzilla entry: 854473 [RESOLVED / FIXED]

SUSE Security Advisories:

    openSUSE-SU-2013:1927-1 openSUSE-SU-2013:1933-1 openSUSE-SU-2013:1960-1 openSUSE-SU-2013:1962-1 openSUSE-SU-2014:0065-1 openSUSE-SU-2014:0092-1

List of released packages

Product(s) Fixed package version(s) References
openSUSE Leap 15.0
  • chromium >= 66.0.3359.170-lp150.1.1
Patchnames:
openSUSE Leap 15.0 GA chromium-66.0.3359.170-lp150.1.1
openSUSE Tumbleweed
  • chromedriver >= 55.0.2883.75-3.1
  • chromium >= 55.0.2883.75-3.1
  • libv8-5 >= 5.3.171-4.1
  • ungoogled-chromium >= 113.0.5672.92-1.1
  • ungoogled-chromium-chromedriver >= 113.0.5672.92-1.1
  • v8 >= 5.3.171-4.1
  • v8-devel >= 5.3.171-4.1
  • v8-private-headers-devel >= 5.3.171-4.1
Patchnames:
openSUSE-Tumbleweed-2024-10171
openSUSE-Tumbleweed-2024-10433
openSUSE-Tumbleweed-2024-12948


SUSE Timeline for this CVE

CVE page created: Sat Dec 7 12:15:25 2013
CVE page last modified: Mon Sep 16 00:14:31 2024