Skip to content
This repository was archived by the owner on Apr 22, 2023. It is now read-only.
This repository was archived by the owner on Apr 22, 2023. It is now read-only.

CVE-2013-2838 v8: Denial of service (out-of-bounds read) via unspecified vector #5535

@tchollingsworth

Description

@tchollingsworth

Common Vulnerabilities and Exposures assigned an identifier CVE-2013-2838 to the following vulnerability:

Google V8, as used in Google Chrome before 27.0.1453.93, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

References:
[1] http://googlechromereleases.blogspot.com/2013/05/stable-channel-release.html
[2] https://code.google.com/p/chromium/issues/detail?id=235311

Upstream patch (covering multiple issues besides #235311):
[3] http://code.google.com/p/v8/source/detail?r=14498

Fedora tracking bug:
[4] https://bugzilla.redhat.com/show_bug.cgi?id=966121

There's no indication whether this affects the V8 3.14 (Node 0.10) branch and that patch contains a bunch of unrelated stuff that certainly isn't backportable so I'm punting this one to you guys to see if any action needs to be taken for node. Thanks!

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions