CVE-2013-6649
Severity CVSS v4.0:
Pending analysis
Type:
CWE-399
Resource Management Errors
Publication date:
28/01/2014
Last modified:
11/04/2025
Description
Use-after-free vulnerability in the RenderSVGImage::paint function in core/rendering/svg/RenderSVGImage.cpp in Blink, as used in Google Chrome before 32.0.1700.102, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving a zero-size SVG image.
Impact
Base Score 2.0
7.50
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | 32.0.1700.101 (including) | |
| cpe:2.3:a:google:chrome:32.0.1700.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:google:chrome:32.0.1700.2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:google:chrome:32.0.1700.3:*:*:*:*:*:*:* | ||
| cpe:2.3:a:google:chrome:32.0.1700.4:*:*:*:*:*:*:* | ||
| cpe:2.3:a:google:chrome:32.0.1700.5:*:*:*:*:*:*:* | ||
| cpe:2.3:a:google:chrome:32.0.1700.6:*:*:*:*:*:*:* | ||
| cpe:2.3:a:google:chrome:32.0.1700.7:*:*:*:*:*:*:* | ||
| cpe:2.3:a:google:chrome:32.0.1700.8:*:*:*:*:*:*:* | ||
| cpe:2.3:a:google:chrome:32.0.1700.9:*:*:*:*:*:*:* | ||
| cpe:2.3:a:google:chrome:32.0.1700.10:*:*:*:*:*:*:* | ||
| cpe:2.3:a:google:chrome:32.0.1700.11:*:*:*:*:*:*:* | ||
| cpe:2.3:a:google:chrome:32.0.1700.12:*:*:*:*:*:*:* | ||
| cpe:2.3:a:google:chrome:32.0.1700.13:*:*:*:*:*:*:* | ||
| cpe:2.3:a:google:chrome:32.0.1700.14:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://crbug.com/330420
- http://googlechromereleases.blogspot.com/2014/01/stable-channel-update_27.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00008.html
- http://www.debian.org/security/2014/dsa-2862
- https://src.chromium.org/viewvc/blink?revision=164536&view=revision
- http://crbug.com/330420
- http://googlechromereleases.blogspot.com/2014/01/stable-channel-update_27.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00008.html
- http://www.debian.org/security/2014/dsa-2862
- https://src.chromium.org/viewvc/blink?revision=164536&view=revision



