HIGH
Heap-based buffer overflow in the ResourceProvider::InitializeSoftware function in cc/resources/resource_provider.cc in Google Chrome before 33.0.1750.146 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a large texture size that triggers improper memory allocation in the software renderer
Published Mar 5, 2014
7.5
HIGHCVSS 2.0
EPSS 1.43%
Description
Heap-based buffer overflow in the ResourceProvider::InitializeSoftware function in cc/resources/resource_provider.cc in Google Chrome before 33.0.1750.146 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a large texture size that triggers improper memory allocation in the software renderer.
Affected products
No data.
OR
- ≤ 33.0.1750.144
- 33.0.1750.0
- 33.0.1750.1
- 33.0.1750.2
- 33.0.1750.3
- 33.0.1750.4
- 33.0.1750.5
- 33.0.1750.6
- 33.0.1750.7
- 33.0.1750.8
- 33.0.1750.9
- 33.0.1750.10
- 33.0.1750.11
- 33.0.1750.12
- 33.0.1750.13
- 33.0.1750.14
- 33.0.1750.15
- 33.0.1750.16
- 33.0.1750.18
- 33.0.1750.19
- 33.0.1750.20
- 33.0.1750.21
- 33.0.1750.22
- 33.0.1750.23
- 33.0.1750.24
- 33.0.1750.25
- 33.0.1750.26
- 33.0.1750.27
- 33.0.1750.28
- 33.0.1750.29
- 33.0.1750.30
- 33.0.1750.31
- 33.0.1750.34
- 33.0.1750.35
- 33.0.1750.36
- 33.0.1750.37
- 33.0.1750.38
- 33.0.1750.39
- 33.0.1750.40
- 33.0.1750.41
- 33.0.1750.42
- 33.0.1750.43
- 33.0.1750.44
- 33.0.1750.45
- 33.0.1750.46
- 33.0.1750.47
- 33.0.1750.48
- 33.0.1750.49
- 33.0.1750.50
- 33.0.1750.51
- 33.0.1750.52
- 33.0.1750.53
- 33.0.1750.54
- 33.0.1750.55
- 33.0.1750.56
- 33.0.1750.57
- 33.0.1750.58
- 33.0.1750.59
- 33.0.1750.60
- 33.0.1750.61
- 33.0.1750.62
- 33.0.1750.63
- 33.0.1750.64
- 33.0.1750.65
- 33.0.1750.66
- 33.0.1750.67
- 33.0.1750.68
- 33.0.1750.69
- 33.0.1750.70
- 33.0.1750.71
- 33.0.1750.73
- 33.0.1750.74
- 33.0.1750.75
- 33.0.1750.76
- 33.0.1750.77
- 33.0.1750.79
- 33.0.1750.80
- 33.0.1750.81
- 33.0.1750.82
- 33.0.1750.83
- 33.0.1750.85
- 33.0.1750.88
- 33.0.1750.89
- 33.0.1750.90
- 33.0.1750.91
- 33.0.1750.92
- 33.0.1750.93
- 33.0.1750.104
- 33.0.1750.106
- 33.0.1750.107
- 33.0.1750.108
- 33.0.1750.109
- 33.0.1750.110
- 33.0.1750.111
- 33.0.1750.112
- 33.0.1750.113
- 33.0.1750.115
- 33.0.1750.116
- 33.0.1750.117
- 33.0.1750.124
- 33.0.1750.125
- 33.0.1750.126
- 33.0.1750.132
- 33.0.1750.133
- 33.0.1750.135
- 33.0.1750.136
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (5)
- http://googlechromereleases.blogspot.com/2014/03/stable-channel-update.html x_refsource_CONFIRMVendor Advisory
- http://www.debian.org/security/2014/dsa-2883 vendor-advisoryx_refsource_DEBIAN
- http://www.securityfocus.com/bid/65930 vdb-entryx_refsource_BID
- https://code.google.com/p/chromium/issues/detail?id=337882 x_refsource_CONFIRM
- https://src.chromium.org/viewvc/chrome?revision=250870&view=revision x_refsource_CONFIRM
| Link | Providers | Tags |
|---|---|---|
| http://googlechromereleases.blogspot.com/2014/03/stable-channel-update.html | x_refsource_CONFIRMVendor Advisory | |
| http://www.debian.org/security/2014/dsa-2883 | vendor-advisoryx_refsource_DEBIAN | |
| http://www.securityfocus.com/bid/65930 | vdb-entryx_refsource_BID | |
| https://code.google.com/p/chromium/issues/detail?id=337882 | x_refsource_CONFIRM | |
| https://src.chromium.org/viewvc/chrome?revision=250870&view=revision | x_refsource_CONFIRM |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Mar 5, 2014
Updated Aug 6, 2024
Reserved Nov 5, 2013
Link CVE-2013-6665
CISA Vulnrichment
Updated n/a