Bug 846444 (CVE-2013-2925) - VUL-0: CVE-2013-2925: chromium : remote denial of service
Summary: VUL-0: CVE-2013-2925: chromium : remote denial of service
Status: RESOLVED FIXED
Alias: CVE-2013-2925
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Major
Target Milestone: ---
Assignee: Forgotten User sM9JzehKpy
QA Contact: Security Team bot
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2013-10-17 15:06 UTC by Victor Pereira
Modified: 2016-04-27 19:58 UTC (History)
1 user (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Victor Pereira 2013-10-17 15:06:17 UTC
CVE-2013-2925

it is a tracker ticker for:

CVE-2013-2926
CVE-2013-2927
CVE-2013-2928

Use-after-free vulnerability in core/xml/XMLHttpRequest.cpp in Blink, as used in Google Chrome before 30.0.1599.101, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger multiple conflicting uses of the same XMLHttpRequest object.


References:
http://googlechromereleases.blogspot.com/2013/10/stable-channel-update_15.html
https://code.google.com/p/chromium/issues/detail?id=292422
https://src.chromium.org/viewvc/blink?revision=158146&view=revision
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-2925
Comment 1 Swamp Workflow Management 2013-10-21 22:00:07 UTC
bugbot adjusting priority
Comment 2 Sebastian Krahmer 2013-12-10 10:15:38 UTC
superseeded by new update version