Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2013-2904

Опубликовано: 21 авг. 2013
Источник: ubuntu
Приоритет: medium
CVSS2: 7.5

Описание

Use-after-free vulnerability in the Document::finishedParsing function in core/dom/Document.cpp in Blink, as used in Google Chrome before 29.0.1547.57, allows remote attackers to cause a denial of service or possibly have unspecified other impact via an onload event that changes an IFRAME element so that its src attribute is no longer an XML document, leading to unintended garbage collection of this document.

РелизСтатусПримечание
devel

not-affected

29.0.1547.65-0ubuntu2
lucid

ignored

end of life
precise

released

30.0.1599.114-0ubuntu0.12.04.3
quantal

released

30.0.1599.114-0ubuntu0.12.10.2
raring

released

30.0.1599.114-0ubuntu0.13.04.2
saucy

not-affected

29.0.1547.65-0ubuntu2
upstream

released

29.0.1547.57

Показывать по

7.5 High

CVSS2

Связанные уязвимости

nvd
больше 12 лет назад

Use-after-free vulnerability in the Document::finishedParsing function in core/dom/Document.cpp in Blink, as used in Google Chrome before 29.0.1547.57, allows remote attackers to cause a denial of service or possibly have unspecified other impact via an onload event that changes an IFRAME element so that its src attribute is no longer an XML document, leading to unintended garbage collection of this document.

debian
больше 12 лет назад

Use-after-free vulnerability in the Document::finishedParsing function ...

github
больше 3 лет назад

Use-after-free vulnerability in the Document::finishedParsing function in core/dom/Document.cpp in Blink, as used in Google Chrome before 29.0.1547.57, allows remote attackers to cause a denial of service or possibly have unspecified other impact via an onload event that changes an IFRAME element so that its src attribute is no longer an XML document, leading to unintended garbage collection of this document.

7.5 High

CVSS2