CVE-2013-6657

NameCVE-2013-6657
Descriptioncore/html/parser/XSSAuditor.cpp in the XSS auditor in Blink, as used in Google Chrome before 33.0.1750.117, inserts the about:blank URL during certain blocking of FORM elements within HTTP requests, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via unspecified vectors.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, GitHub code/issues, web search, more)
ReferencesDSA-2883-1
NVD severitymedium (attack range: remote)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
chromium-browser (PTS)wheezy (security), wheezy37.0.2062.120-1~deb7u1fixed
jessie53.0.2785.89-1~deb8u1fixed
jessie (security)53.0.2785.143-1~deb8u1fixed
stretch53.0.2785.143-1fixed
sid55.0.2883.75-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
chromium-browsersource(unstable)33.0.1750.152-1medium
chromium-browsersourcesqueeze(unfixed)end-of-life
chromium-browsersourcewheezy33.0.1750.152-1~deb7u1mediumDSA-2883-1

Search for package or bug name: Reporting problems