CVE-2013-6631

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
19/11/2013
Last modified:
11/04/2025

Description

Use-after-free vulnerability in the Channel::SendRTCPPacket function in voice_engine/channel.cc in libjingle in WebRTC, as used in Google Chrome before 31.0.1650.48 and other products, allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via vectors that trigger the absence of certain statistics initialization, leading to the skipping of a required DeRegisterExternalTransport call.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* 31.0.1650.47 (including)
cpe:2.3:a:google:chrome:31.0.1650.0:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:31.0.1650.2:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:31.0.1650.3:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:31.0.1650.4:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:31.0.1650.5:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:31.0.1650.6:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:31.0.1650.7:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:31.0.1650.8:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:31.0.1650.9:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:31.0.1650.10:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:31.0.1650.11:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:31.0.1650.12:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:31.0.1650.13:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:31.0.1650.14:*:*:*:*:*:*:*