Input validation error in SUSE products - CVE-2013-6650

 

Input validation error in SUSE products - CVE-2013-6650

Published: January 28, 2014 / Updated: August 10, 2020


Vulnerability identifier: #VU42098
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2013-6650
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

The StoreBuffer::ExemptPopularPages function in store-buffer.cc in Google V8 before 3.22.24.16, as used in Google Chrome before 32.0.1700.102, allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via vectors that trigger incorrect handling of "popular pages."


Affected software

Debian Linux
Opensuse
Fedora
Google Chrome
v8

How to mitigate CVE-2013-6650

Install update from vendor's website.

v8 - update to 3.14.5.10-6.el6

External References

Related Security Bulletins