Code Injection in Google Chrome - CVE-2013-0912
Published: March 11, 2013 / Updated: August 11, 2020
Vulnerability identifier: #VU43012
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2013-0912
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
WebKit in Google Chrome before 25.0.1364.160 allows remote attackers to execute arbitrary code via vectors that leverage "type confusion."
Affected software
Google Chrome
How to mitigate CVE-2013-0912
Install update from vendor's website.
External References
- http://googlechromereleases.blogspot.com/2013/03/stable-channel-update_7.html
- http://h30499.www3.hp.com/t5/HP-Security-Research-Blog/Pwn2Own-2013/ba-p/5981157
- http://labs.mwrinfosecurity.com/blog/2013/03/06/pwn2own-at-cansecwest-2013/
- http://lists.apple.com/archives/security-announce/2013/Apr/msg00000.html
- http://lists.apple.com/archives/security-announce/2013/Mar/msg00004.html
- http://support.apple.com/kb/HT5701
- http://support.apple.com/kb/HT5704
- http://twitter.com/thezdi/statuses/309460019131346944
- https://code.google.com/p/chromium/issues/detail?id=180763
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16274