CVE-2013-2904

NameCVE-2013-2904
DescriptionUse-after-free vulnerability in the Document::finishedParsing function in core/dom/Document.cpp in Blink, as used in Google Chrome before 29.0.1547.57, allows remote attackers to cause a denial of service or possibly have unspecified other impact via an onload event that changes an IFRAME element so that its src attribute is no longer an XML document, leading to unintended garbage collection of this document.
SourceCVE (at NVD; oss-sec, fulldisc, OSVDB, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, more)
ReferencesDSA-2741-1
NVD severityhigh (attack range: remote)
Debian/oldoldstablepackage chromium-browser is vulnerable.
Debian/oldstablenot vulnerable.
Debian/stablenot vulnerable.
Debian/testingnot vulnerable.
Debian/unstablenot vulnerable.

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
chromium-browser (PTS)squeeze, squeeze (security)6.0.472.63~r59945-5+squeeze6vulnerable
wheezy (security), wheezy37.0.2062.120-1~deb7u1fixed
jessie43.0.2357.65-1~deb8u1fixed
jessie (security)44.0.2403.89-1~deb8u1fixed
stretch44.0.2403.107-1fixed
sid44.0.2403.157-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
chromium-browsersource(unstable)29.0.1547.57-1high
chromium-browsersourcesqueeze(unfixed)end-of-life
chromium-browsersourcewheezy29.0.1547.57-1~deb7u1highDSA-2741-1

Search for package or bug name: Reporting problems