Your submission was sent successfully! Close

CVE-2013-6638

Published: 7 December 2013

Multiple buffer overflows in runtime.cc in Google V8 before 3.22.24.7, as used in Google Chrome before 31.0.1650.63, allow remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger a large typed array, related to the (1) Runtime_TypedArrayInitialize and (2) Runtime_TypedArrayInitializeFromArrayLike functions.

Notes

AuthorNote
mikesalvatore
The Ubuntu Security Team does not support libv8
Priority

Medium

Status

Package Release Status
chromium-browser
Launchpad, Ubuntu, Debian
artful Not vulnerable
(31.0.1650.63-0ubuntu1~20131204.1)
bionic Not vulnerable
(31.0.1650.63-0ubuntu1~20131204.1)
cosmic Not vulnerable
(31.0.1650.63-0ubuntu1~20131204.1)
disco Not vulnerable
(31.0.1650.63-0ubuntu1~20131204.1)
lucid Ignored
(reached end-of-life)
precise Does not exist
(precise was released [31.0.1650.63-0ubuntu0.12.04.1~20131204.1])
quantal
Released (31.0.1650.63-0ubuntu0.12.10.1~20131204.1)
raring
Released (31.0.1650.63-0ubuntu0.13.04.1~20131204.1)
saucy
Released (31.0.1650.63-0ubuntu0.13.10.1~20131204.1)
trusty Does not exist
(trusty was not-affected [31.0.1650.63-0ubuntu1~20131204.1])
upstream
Released (31.0.1650.63)
utopic Not vulnerable
(31.0.1650.63-0ubuntu1~20131204.1)
vivid Does not exist

wily Not vulnerable
(31.0.1650.63-0ubuntu1~20131204.1)
xenial Not vulnerable
(31.0.1650.63-0ubuntu1~20131204.1)
yakkety Not vulnerable
(31.0.1650.63-0ubuntu1~20131204.1)
zesty Not vulnerable
(31.0.1650.63-0ubuntu1~20131204.1)
libv8
Launchpad, Ubuntu, Debian
artful Does not exist

bionic Does not exist

cosmic Does not exist

disco Does not exist

lucid Ignored
(reached end-of-life)
precise Does not exist
(precise was needs-triage)
quantal Ignored
(reached end-of-life)
raring Ignored
(reached end-of-life)
saucy Ignored
(reached end-of-life)
trusty Does not exist

upstream Needs triage

utopic Does not exist

vivid Does not exist

wily Does not exist

xenial Does not exist

yakkety Does not exist

zesty Does not exist

libv8-3.14
Launchpad, Ubuntu, Debian
artful Ignored
(reached end-of-life)
bionic Ignored
(libv8 not supported)
cosmic Ignored
(libv8 not supported)
disco Ignored
(libv8 not supported)
lucid Does not exist

precise Does not exist

quantal Does not exist

raring Does not exist

saucy Ignored
(reached end-of-life)
trusty Does not exist
(trusty was ignored [libv8 not supported])
upstream Needed

utopic Ignored
(reached end-of-life)
vivid Does not exist

wily Ignored
(reached end-of-life)
xenial Ignored
(libv8 not supported)
yakkety Ignored
(reached end-of-life)
zesty Ignored
(reached end-of-life)
qtjsbackend-opensource-src
Launchpad, Ubuntu, Debian
artful Does not exist

bionic Does not exist

cosmic Does not exist

disco Does not exist

lucid Does not exist

precise Does not exist

quantal Does not exist

raring Ignored
(see note)
saucy Ignored
(see note)
trusty Does not exist

upstream Needs triage

utopic Does not exist

vivid Does not exist

wily Does not exist

xenial Does not exist

yakkety Does not exist

zesty Does not exist