CVE-2013-6650
high
CVSS v3
—
CVSS v2
7.5
VIR risk
7.5
Description
The StoreBuffer::ExemptPopularPages function in store-buffer.cc in Google V8 before 3.22.24.16, as used in Google Chrome before 32.0.1700.102, allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via vectors that trigger incorrect handling of "popular pages."
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cve@mitre.org — http://googlechromereleases.blogspot.com/2014/01/stable-channel-update_27.html
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| suse | 12.3 | affected | |
| suse | 13.1 | affected | |
| debian | 7.0 | affected | |
| debian | 8.0 | affected | |
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| chrome | {"endIncluding":"32.0.1700.101"} | | |
| chrome | 32.0.1700.0 | | |
| chrome | 32.0.1700.2 | | |
| chrome | 32.0.1700.3 | | |
| chrome | 32.0.1700.4 | | |
| chrome | 32.0.1700.5 | | |
| chrome | 32.0.1700.6 | | |
| chrome | 32.0.1700.7 | | |
| chrome | 32.0.1700.8 | | |
| chrome | 32.0.1700.9 | | |
| chrome | 32.0.1700.10 | | |
| chrome | 32.0.1700.11 | | |
| chrome | 32.0.1700.12 | | |
| chrome | 32.0.1700.13 | | |
| chrome | 32.0.1700.14 | | |
| chrome | 32.0.1700.15 | | |
| chrome | 32.0.1700.16 | | |
| chrome | 32.0.1700.17 | | |
| chrome | 32.0.1700.18 | | |
| chrome | 32.0.1700.19 | | |
| chrome | 32.0.1700.21 | | |
| chrome | 32.0.1700.22 | | |
| chrome | 32.0.1700.23 | | |
| chrome | 32.0.1700.24 | | |
| chrome | 32.0.1700.26 | | |
| chrome | 32.0.1700.27 | | |
| chrome | 32.0.1700.28 | | |
| chrome | 32.0.1700.29 | | |
| chrome | 32.0.1700.30 | | |
| chrome | 32.0.1700.31 | | |
| chrome | 32.0.1700.32 | | |
| chrome | 32.0.1700.33 | | |
| chrome | 32.0.1700.34 | | |
| chrome | 32.0.1700.35 | | |
| chrome | 32.0.1700.38 | | |
| chrome | 32.0.1700.39 | | |
| chrome | 32.0.1700.41 | | |
| chrome | 32.0.1700.50 | | |
| chrome | 32.0.1700.51 | | |
| chrome | 32.0.1700.52 | | |
| chrome | 32.0.1700.53 | | |
| chrome | 32.0.1700.54 | | |
| chrome | 32.0.1700.55 | | |
| chrome | 32.0.1700.56 | | |
| chrome | 32.0.1700.57 | | |
| chrome | 32.0.1700.58 | | |
| chrome | 32.0.1700.59 | | |
| chrome | 32.0.1700.62 | | |
| chrome | 32.0.1700.63 | | |
| chrome | 32.0.1700.64 | | |
| chrome | 32.0.1700.65 | | |
| chrome | 32.0.1700.66 | | |
| chrome | 32.0.1700.67 | | |
| chrome | 32.0.1700.68 | | |
| chrome | 32.0.1700.69 | | |
| chrome | 32.0.1700.70 | | |
| chrome | 32.0.1700.71 | | |
| chrome | 32.0.1700.72 | | |
| chrome | 32.0.1700.74 | | |
| chrome | 32.0.1700.75 | | |
| chrome | 32.0.1700.76 | | |
| chrome | 32.0.1700.77 | | |
| chrome | 32.0.1700.94 | | |
| chrome | 32.0.1700.95 | | |
| chrome | 32.0.1700.96 | | |
| chrome | 32.0.1700.97 | | |
| chrome | 32.0.1700.98 | | |
| chrome | 32.0.1700.99 | | |
| chrome | 32.0.1700.100 | |
References
- http://crbug.com/331444
- http://googlechromereleases.blogspot.com/2014/01/stable-channel-update_27.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00008.html
- http://www.debian.org/security/2014/dsa-2862
- https://code.google.com/p/v8/source/detail?r=18483
- http://crbug.com/331444
- http://googlechromereleases.blogspot.com/2014/01/stable-channel-update_27.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00008.html
- http://www.debian.org/security/2014/dsa-2862
- https://code.google.com/p/v8/source/detail?r=18483
CWEs
CWE-20
Verify integrity in audit chain (admin only). AS-IS.