MEDIUM
Double free vulnerability in the ResourceFetcher::didLoadResource function in core/fetch/ResourceFetcher.cpp in the resource loader in Blink, as used in Google Chrome before 30.0.1599.66, allows remote attackers to cause a denial of service or possibly have unspecified other impact by triggering certain callback processing during the reporting of a resource entry
Published Oct 2, 2013
6.8
MEDIUMCVSS 2.0
EPSS 1.27%
Description
Double free vulnerability in the ResourceFetcher::didLoadResource function in core/fetch/ResourceFetcher.cpp in the resource loader in Blink, as used in Google Chrome before 30.0.1599.66, allows remote attackers to cause a denial of service or possibly have unspecified other impact by triggering certain callback processing during the reporting of a resource entry.
Affected products
No data.
OR
- ≤ 30.0.1599.65
- 30.0.1599.0
- 30.0.1599.1
- 30.0.1599.2
- 30.0.1599.4
- 30.0.1599.5
- 30.0.1599.6
- 30.0.1599.7
- 30.0.1599.8
- 30.0.1599.9
- 30.0.1599.10
- 30.0.1599.11
- 30.0.1599.12
- 30.0.1599.13
- 30.0.1599.14
- 30.0.1599.15
- 30.0.1599.16
- 30.0.1599.17
- 30.0.1599.18
- 30.0.1599.19
- 30.0.1599.20
- 30.0.1599.21
- 30.0.1599.22
- 30.0.1599.23
- 30.0.1599.24
- 30.0.1599.25
- 30.0.1599.26
- 30.0.1599.27
- 30.0.1599.28
- 30.0.1599.29
- 30.0.1599.30
- 30.0.1599.31
- 30.0.1599.32
- 30.0.1599.33
- 30.0.1599.34
- 30.0.1599.35
- 30.0.1599.36
- 30.0.1599.37
- 30.0.1599.38
- 30.0.1599.39
- 30.0.1599.40
- 30.0.1599.41
- 30.0.1599.42
- 30.0.1599.43
- 30.0.1599.44
- 30.0.1599.47
- 30.0.1599.48
- 30.0.1599.49
- 30.0.1599.50
- 30.0.1599.51
- 30.0.1599.52
- 30.0.1599.53
- 30.0.1599.56
- 30.0.1599.57
- 30.0.1599.58
- 30.0.1599.59
- 30.0.1599.60
- 30.0.1599.61
- 30.0.1599.64
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (9)
- http://googlechromereleases.blogspot.com/2013/10/stable-channel-update.html x_refsource_CONFIRM
- http://lists.opensuse.org/opensuse-security-announce/2013-10/msg00002.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2013-12/msg00002.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-updates/2014-01/msg00042.html vendor-advisoryx_refsource_SUSE
- http://www.debian.org/security/2013/dsa-2785 vendor-advisoryx_refsource_DEBIAN
- https://code.google.com/p/chromium/issues/detail?id=286414 x_refsource_CONFIRM
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2013-2860 Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18389 vdb-entrysignaturex_refsource_OVAL
- https://src.chromium.org/viewvc/blink?revision=157760&view=revision x_refsource_CONFIRM
| Link | Providers | Tags |
|---|---|---|
| http://googlechromereleases.blogspot.com/2013/10/stable-channel-update.html | x_refsource_CONFIRM | |
| http://lists.opensuse.org/opensuse-security-announce/2013-10/msg00002.html | vendor-advisoryx_refsource_SUSE | |
| http://lists.opensuse.org/opensuse-security-announce/2013-12/msg00002.html | vendor-advisoryx_refsource_SUSE | |
| http://lists.opensuse.org/opensuse-updates/2014-01/msg00042.html | vendor-advisoryx_refsource_SUSE | |
| http://www.debian.org/security/2013/dsa-2785 | vendor-advisoryx_refsource_DEBIAN | |
| https://code.google.com/p/chromium/issues/detail?id=286414 | x_refsource_CONFIRM | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2013-2860 | Advisory | |
| https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18389 | vdb-entrysignaturex_refsource_OVAL | |
| https://src.chromium.org/viewvc/blink?revision=157760&view=revision | x_refsource_CONFIRM |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Chrome
Published Oct 2, 2013
Updated Aug 6, 2024
Reserved Apr 11, 2013
Link CVE-2013-2921
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2013-2860 Assigner Chrome
Published Oct 2, 2013
Updated Aug 6, 2024
Exploited since n/a
Link EUVD-2013-2860