v8: DoS (out-of-bounds read) in DehoistArrayIndex function in hydrogen.cc
Published Dec 7, 2013
7.5
HIGHCVSS 2.0
EPSS 1.76%
Description
The DehoistArrayIndex function in hydrogen-dehoist.cc (aka hydrogen.cc) in Google V8 before 3.22.24.7, as used in Google Chrome before 31.0.1650.63, allows remote attackers to cause a denial of service (out-of-bounds read) via JavaScript code that sets a variable to the value of an array element with a crafted index.
Affected products
No data.
- ≤ 31.0.1650.62
- 31.0.1650.0
- 31.0.1650.2
- 31.0.1650.3
- 31.0.1650.4
- 31.0.1650.5
- 31.0.1650.6
- 31.0.1650.7
- 31.0.1650.8
- 31.0.1650.9
- 31.0.1650.10
- 31.0.1650.11
- 31.0.1650.12
- 31.0.1650.13
- 31.0.1650.14
- 31.0.1650.15
- 31.0.1650.16
- 31.0.1650.17
- 31.0.1650.18
- 31.0.1650.19
- 31.0.1650.20
- 31.0.1650.22
- 31.0.1650.23
- 31.0.1650.25
- 31.0.1650.26
- 31.0.1650.27
- 31.0.1650.28
- 31.0.1650.29
- 31.0.1650.30
- 31.0.1650.31
- 31.0.1650.32
- 31.0.1650.33
- 31.0.1650.34
- 31.0.1650.35
- 31.0.1650.36
- 31.0.1650.37
- 31.0.1650.38
- 31.0.1650.39
- 31.0.1650.41
- 31.0.1650.42
- 31.0.1650.43
- 31.0.1650.44
- 31.0.1650.45
- 31.0.1650.46
- 31.0.1650.47
- 31.0.1650.48
- 31.0.1650.49
- 31.0.1650.50
- 31.0.1650.51
- 31.0.1650.52
- 31.0.1650.53
- 31.0.1650.54
- 31.0.1650.55
- 31.0.1650.57
- 31.0.1650.58
- 31.0.1650.59
- 31.0.1650.60
- 31.0.1650.61
- ≤ 3.22.24
- 3.22.0
- 3.22.1
- 3.22.2
- 3.22.3
- 3.22.4
- 3.22.5
- 3.22.6
- 3.22.7
- 3.22.8
- 3.22.9
- 3.22.10
- 3.22.11
- 3.22.12
- 3.22.13
- 3.22.14
- 3.22.15
- 3.22.16
- 3.22.17
- 3.22.18
- 3.22.19
- 3.22.20
- 3.22.21
- 3.22.22
- 3.22.23
No data.
Red Hat Satellite 6.0
v8-1:3.14.5.10-11.el7sat
Fixed · RHEA-2014:1175
Red Hat Satellite 6.0
v8-1:3.14.5.10-11.el7sat
Fixed · RHEA-2014:1175
Red Hat Software Collections 1 for Red Hat Enterprise Linux 6
v8314-v8-1:3.14.5.10-6.el6
Fixed · RHSA-2014:1744
Red Hat Software Collections 1 for Red Hat Enterprise Linux 6.4 EUS
v8314-v8-1:3.14.5.10-6.el6
Fixed · RHSA-2014:1744
Red Hat Software Collections 1 for Red Hat Enterprise Linux 6.5 EUS
v8314-v8-1:3.14.5.10-6.el6
Fixed · RHSA-2014:1744
Red Hat Software Collections 1 for Red Hat Enterprise Linux 7
v8314-v8-1:3.14.5.10-6.el7
Fixed · RHSA-2014:1744
CloudForms Management Engine 5
ruby193-v8
Will not fix
OpenShift Enterprise 1
ruby193-v8
Will not fix
Red Hat OpenShift Enterprise 2
v8
Will not fix
Red Hat OpenStack Platform 3
ruby193-v8
Will not fix
Red Hat OpenStack Platform 3
v8
Will not fix
Red Hat OpenStack Platform 4
ruby193-v8
Will not fix
Red Hat OpenStack Platform 4
v8
Will not fix
Red Hat Subscription Asset Manager
ruby193-v8
Will not fix
Red Hat Subscription Asset Manager
v8
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Satellite 6.0 | v8-1:3.14.5.10-11.el7sat | Fixed | RHEA-2014:1175 |
| Red Hat Satellite 6.0 | v8-1:3.14.5.10-11.el7sat | Fixed | RHEA-2014:1175 |
| Red Hat Software Collections 1 for Red Hat Enterprise Linux 6 | v8314-v8-1:3.14.5.10-6.el6 | Fixed | RHSA-2014:1744 |
| Red Hat Software Collections 1 for Red Hat Enterprise Linux 6.4 EUS | v8314-v8-1:3.14.5.10-6.el6 | Fixed | RHSA-2014:1744 |
| Red Hat Software Collections 1 for Red Hat Enterprise Linux 6.5 EUS | v8314-v8-1:3.14.5.10-6.el6 | Fixed | RHSA-2014:1744 |
| Red Hat Software Collections 1 for Red Hat Enterprise Linux 7 | v8314-v8-1:3.14.5.10-6.el7 | Fixed | RHSA-2014:1744 |
| CloudForms Management Engine 5 | ruby193-v8 | Will not fix | n/a |
| OpenShift Enterprise 1 | ruby193-v8 | Will not fix | n/a |
| Red Hat OpenShift Enterprise 2 | v8 | Will not fix | n/a |
| Red Hat OpenStack Platform 3 | ruby193-v8 | Will not fix | n/a |
| Red Hat OpenStack Platform 3 | v8 | Will not fix | n/a |
| Red Hat OpenStack Platform 4 | ruby193-v8 | Will not fix | n/a |
| Red Hat OpenStack Platform 4 | v8 | Will not fix | n/a |
| Red Hat Subscription Asset Manager | ruby193-v8 | Will not fix | n/a |
| Red Hat Subscription Asset Manager | v8 | Will not fix | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (18)
- http://code.google.com/p/v8/source/detail?r=17801 x_refsource_CONFIRMPatch
- http://googlechromereleases.blogspot.com/2013/12/stable-channel-update.html x_refsource_CONFIRMVendor Advisory
- http://lists.opensuse.org/opensuse-updates/2013-12/msg00090.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-updates/2013-12/msg00096.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-updates/2013-12/msg00122.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-updates/2013-12/msg00124.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-updates/2014-01/msg00042.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-updates/2014-01/msg00063.html vendor-advisoryx_refsource_SUSE
- http://secunia.com/advisories/56216 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/56217 third-party-advisoryx_refsource_SECUNIA
- http://www.debian.org/security/2013/dsa-2811 vendor-advisoryx_refsource_DEBIAN
- http://www.securitytracker.com/id/1029442 vdb-entryx_refsource_SECTRACK
- https://access.redhat.com/security/cve/CVE-2013-6640 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1039889 Issue Tracking
- https://code.google.com/p/chromium/issues/detail?id=319860 x_refsource_CONFIRM
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2013-6442 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2013-6640
- https://www.cve.org/CVERecord?id=CVE-2013-6640
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub
No data