CVE-2013-6636

Publication date 7 December 2013

Last updated 24 July 2024


Ubuntu priority

Description

The FrameLoader::notifyIfInitialDocumentAccessed function in core/loader/FrameLoader.cpp in Blink, as used in Google Chrome before 31.0.1650.63, makes an incorrect check for an empty document during presentation of a modal dialog, which allows remote attackers to spoof the address bar via vectors involving the document.write method.

Status

Package Ubuntu Release Status
chromium-browser 13.10 saucy
Fixed 31.0.1650.63-0ubuntu0.13.10.1~20131204.1
13.04 raring
Fixed 31.0.1650.63-0ubuntu0.13.04.1~20131204.1
12.10 quantal
Fixed 31.0.1650.63-0ubuntu0.12.10.1~20131204.1
12.04 LTS precise
Fixed 31.0.1650.63-0ubuntu0.12.04.1~20131204.1
10.04 LTS lucid Ignored end of life


Access our resources on patching vulnerabilities