MEDIUM
webkitgtk: out-of-bounds read in the SVG implementation (WSA-2015-0001)
Published Jul 10, 2013
5.0
MEDIUMCVSS 2.0
EPSS 1.69%
Description
core/rendering/svg/SVGInlineTextBox.cpp in the SVG implementation in Blink, as used in Google Chrome before 28.0.1500.71, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
Affected products
No data.
OR
- ≤ 28.0.1500.70
- 28.0.1500.0
- 28.0.1500.2
- 28.0.1500.3
- 28.0.1500.4
- 28.0.1500.5
- 28.0.1500.6
- 28.0.1500.8
- 28.0.1500.9
- 28.0.1500.10
- 28.0.1500.11
- 28.0.1500.12
- 28.0.1500.13
- 28.0.1500.14
- 28.0.1500.15
- 28.0.1500.16
- 28.0.1500.17
- 28.0.1500.18
- 28.0.1500.19
- 28.0.1500.20
- 28.0.1500.21
- 28.0.1500.22
- 28.0.1500.23
- 28.0.1500.24
- 28.0.1500.25
- 28.0.1500.26
- 28.0.1500.27
- 28.0.1500.28
- 28.0.1500.29
- 28.0.1500.31
- 28.0.1500.32
- 28.0.1500.33
- 28.0.1500.34
- 28.0.1500.35
- 28.0.1500.36
- 28.0.1500.37
- 28.0.1500.38
- 28.0.1500.39
- 28.0.1500.40
- 28.0.1500.41
- 28.0.1500.42
- 28.0.1500.43
- 28.0.1500.44
- 28.0.1500.45
- 28.0.1500.46
- 28.0.1500.47
- 28.0.1500.48
- 28.0.1500.49
- 28.0.1500.50
- 28.0.1500.51
- 28.0.1500.52
- 28.0.1500.53
- 28.0.1500.54
- 28.0.1500.56
- 28.0.1500.58
- 28.0.1500.59
- 28.0.1500.60
- 28.0.1500.61
- 28.0.1500.62
- 28.0.1500.63
- 28.0.1500.64
- 28.0.1500.66
- 28.0.1500.68
No data.
Red Hat Enterprise Linux 6
webkitgtk
Will not fix
Red Hat Enterprise Linux 7
webkitgtk3
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | webkitgtk | Will not fix | n/a |
| Red Hat Enterprise Linux 7 | webkitgtk3 | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Product Security has rated this issue as having Moderate security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Weaknesses (2)
References (15)
- http://archives.neohapsis.com/archives/bugtraq/2014-05/0128.html vendor-advisoryx_refsource_APPLE
- http://archives.neohapsis.com/archives/bugtraq/2014-06/0174.html vendor-advisoryx_refsource_APPLE
- http://archives.neohapsis.com/archives/bugtraq/2014-06/0175.html vendor-advisoryx_refsource_APPLE
- http://googlechromereleases.blogspot.com/2013/07/stable-channel-update.html x_refsource_CONFIRM
- http://src.chromium.org/viewvc/blink?revision=150456&view=revision x_refsource_CONFIRM
- http://support.apple.com/kb/HT6254 x_refsource_CONFIRM
- http://webkitgtk.org/security/WSA-2015-0001.html
- http://www.debian.org/security/2013/dsa-2724 vendor-advisoryx_refsource_DEBIAN
- https://access.redhat.com/security/cve/CVE-2013-2875 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1186232 Issue Tracking
- https://code.google.com/p/chromium/issues/detail?id=233848 x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2013-2875
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17227 vdb-entrysignaturex_refsource_OVAL
- https://support.apple.com/kb/HT6537 x_refsource_CONFIRM
- https://www.cve.org/CVERecord?id=CVE-2013-2875
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Chrome
Published Jul 10, 2013
Updated Aug 6, 2024
Reserved Apr 11, 2013
Link CVE-2013-2875
CISA Vulnrichment
Updated n/a