HIGH
Use-after-free vulnerability in the Channel::SendRTCPPacket function in voice_engine/channel.cc in libjingle in WebRTC, as used in Google Chrome before 31.0.1650.48 and other products, allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via vectors that trigger the absence of certain statistics initialization, leading to the skipping of a required DeRegisterExternalTransport call
Published Nov 15, 2013
7.5
HIGHCVSS 2.0
EPSS 1.61%
Description
Use-after-free vulnerability in the Channel::SendRTCPPacket function in voice_engine/channel.cc in libjingle in WebRTC, as used in Google Chrome before 31.0.1650.48 and other products, allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via vectors that trigger the absence of certain statistics initialization, leading to the skipping of a required DeRegisterExternalTransport call.
Affected products
No data.
OR
- ≤ 31.0.1650.47
- 31.0.1650.0
- 31.0.1650.2
- 31.0.1650.3
- 31.0.1650.4
- 31.0.1650.5
- 31.0.1650.6
- 31.0.1650.7
- 31.0.1650.8
- 31.0.1650.9
- 31.0.1650.10
- 31.0.1650.11
- 31.0.1650.12
- 31.0.1650.13
- 31.0.1650.14
- 31.0.1650.15
- 31.0.1650.16
- 31.0.1650.17
- 31.0.1650.18
- 31.0.1650.19
- 31.0.1650.20
- 31.0.1650.22
- 31.0.1650.23
- 31.0.1650.25
- 31.0.1650.26
- 31.0.1650.27
- 31.0.1650.28
- 31.0.1650.29
- 31.0.1650.30
- 31.0.1650.31
- 31.0.1650.32
- 31.0.1650.33
- 31.0.1650.34
- 31.0.1650.35
- 31.0.1650.36
- 31.0.1650.37
- 31.0.1650.38
- 31.0.1650.39
- 31.0.1650.41
- 31.0.1650.42
- 31.0.1650.43
- 31.0.1650.44
- 31.0.1650.45
- 31.0.1650.46
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (0)
No CWE recorded.
References (9)
- http://googlechromereleases.blogspot.com/2013/11/stable-channel-update.html x_refsource_CONFIRMVendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2013-11/msg00025.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2013-11/msg00026.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2013-12/msg00002.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-updates/2014-01/msg00042.html vendor-advisoryx_refsource_SUSE
- http://www.debian.org/security/2013/dsa-2799 vendor-advisoryx_refsource_DEBIAN
- https://code.google.com/p/chromium/issues/detail?id=296804 x_refsource_CONFIRM
- https://code.google.com/p/webrtc/source/detail?r=4827 x_refsource_CONFIRM
- https://webrtc-codereview.appspot.com/2275008 x_refsource_CONFIRMPatch
| Link | Providers | Tags |
|---|---|---|
| http://googlechromereleases.blogspot.com/2013/11/stable-channel-update.html | x_refsource_CONFIRMVendor Advisory | |
| http://lists.opensuse.org/opensuse-security-announce/2013-11/msg00025.html | vendor-advisoryx_refsource_SUSE | |
| http://lists.opensuse.org/opensuse-security-announce/2013-11/msg00026.html | vendor-advisoryx_refsource_SUSE | |
| http://lists.opensuse.org/opensuse-security-announce/2013-12/msg00002.html | vendor-advisoryx_refsource_SUSE | |
| http://lists.opensuse.org/opensuse-updates/2014-01/msg00042.html | vendor-advisoryx_refsource_SUSE | |
| http://www.debian.org/security/2013/dsa-2799 | vendor-advisoryx_refsource_DEBIAN | |
| https://code.google.com/p/chromium/issues/detail?id=296804 | x_refsource_CONFIRM | |
| https://code.google.com/p/webrtc/source/detail?r=4827 | x_refsource_CONFIRM | |
| https://webrtc-codereview.appspot.com/2275008 | x_refsource_CONFIRMPatch |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Nov 15, 2013
Updated Aug 6, 2024
Reserved Nov 5, 2013
Link CVE-2013-6631
CISA Vulnrichment
Updated n/a