CVE-2013-6627

net/http/http_stream_parser.cc in Google Chrome before 31.0.1650.48 does not properly process HTTP Informational (aka 1xx) status codes, which allows remote web servers to cause a denial of service (out-of-bounds read) via a crafted response.
References
Link Resource
http://blog.skylined.nl/20161219001.html
http://googlechromereleases.blogspot.com/2013/11/stable-channel-update.html Vendor Advisory
http://lists.opensuse.org/opensuse-security-announce/2013-11/msg00025.html
http://lists.opensuse.org/opensuse-security-announce/2013-11/msg00026.html
http://lists.opensuse.org/opensuse-security-announce/2013-12/msg00002.html
http://lists.opensuse.org/opensuse-updates/2014-01/msg00042.html
http://packetstormsecurity.com/files/140209/Chrome-HTTP-1xx-Out-Of-Bounds-Read.html
http://seclists.org/fulldisclosure/2016/Dec/65
http://www.debian.org/security/2013/dsa-2799
https://code.google.com/p/chromium/issues/detail?id=299892
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19113
https://src.chromium.org/viewvc/chrome?revision=226539&view=revision
https://www.exploit-db.com/exploits/40944/
http://blog.skylined.nl/20161219001.html
http://googlechromereleases.blogspot.com/2013/11/stable-channel-update.html Vendor Advisory
http://lists.opensuse.org/opensuse-security-announce/2013-11/msg00025.html
http://lists.opensuse.org/opensuse-security-announce/2013-11/msg00026.html
http://lists.opensuse.org/opensuse-security-announce/2013-12/msg00002.html
http://lists.opensuse.org/opensuse-updates/2014-01/msg00042.html
http://packetstormsecurity.com/files/140209/Chrome-HTTP-1xx-Out-Of-Bounds-Read.html
http://seclists.org/fulldisclosure/2016/Dec/65
http://www.debian.org/security/2013/dsa-2799
https://code.google.com/p/chromium/issues/detail?id=299892
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19113
https://src.chromium.org/viewvc/chrome?revision=226539&view=revision
https://www.exploit-db.com/exploits/40944/
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:31.0.1650.0:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:31.0.1650.2:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:31.0.1650.3:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:31.0.1650.4:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:31.0.1650.5:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:31.0.1650.6:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:31.0.1650.7:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:31.0.1650.8:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:31.0.1650.9:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:31.0.1650.10:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:31.0.1650.11:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:31.0.1650.12:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:31.0.1650.13:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:31.0.1650.14:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:31.0.1650.15:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:31.0.1650.16:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:31.0.1650.17:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:31.0.1650.18:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:31.0.1650.19:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:31.0.1650.20:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:31.0.1650.22:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:31.0.1650.23:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:31.0.1650.25:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:31.0.1650.26:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:31.0.1650.27:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:31.0.1650.28:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:31.0.1650.29:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:31.0.1650.30:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:31.0.1650.31:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:31.0.1650.32:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:31.0.1650.33:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:31.0.1650.34:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:31.0.1650.35:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:31.0.1650.36:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:31.0.1650.37:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:31.0.1650.38:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:31.0.1650.39:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:31.0.1650.41:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:31.0.1650.42:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:31.0.1650.43:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:31.0.1650.44:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:31.0.1650.45:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:31.0.1650.46:*:*:*:*:*:*:*

History

21 Nov 2024, 01:59

Type Values Removed Values Added
References () http://blog.skylined.nl/20161219001.html - () http://blog.skylined.nl/20161219001.html -
References () http://googlechromereleases.blogspot.com/2013/11/stable-channel-update.html - Vendor Advisory () http://googlechromereleases.blogspot.com/2013/11/stable-channel-update.html - Vendor Advisory
References () http://lists.opensuse.org/opensuse-security-announce/2013-11/msg00025.html - () http://lists.opensuse.org/opensuse-security-announce/2013-11/msg00025.html -
References () http://lists.opensuse.org/opensuse-security-announce/2013-11/msg00026.html - () http://lists.opensuse.org/opensuse-security-announce/2013-11/msg00026.html -
References () http://lists.opensuse.org/opensuse-security-announce/2013-12/msg00002.html - () http://lists.opensuse.org/opensuse-security-announce/2013-12/msg00002.html -
References () http://lists.opensuse.org/opensuse-updates/2014-01/msg00042.html - () http://lists.opensuse.org/opensuse-updates/2014-01/msg00042.html -
References () http://packetstormsecurity.com/files/140209/Chrome-HTTP-1xx-Out-Of-Bounds-Read.html - () http://packetstormsecurity.com/files/140209/Chrome-HTTP-1xx-Out-Of-Bounds-Read.html -
References () http://seclists.org/fulldisclosure/2016/Dec/65 - () http://seclists.org/fulldisclosure/2016/Dec/65 -
References () http://www.debian.org/security/2013/dsa-2799 - () http://www.debian.org/security/2013/dsa-2799 -
References () https://code.google.com/p/chromium/issues/detail?id=299892 - () https://code.google.com/p/chromium/issues/detail?id=299892 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19113 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19113 -
References () https://src.chromium.org/viewvc/chrome?revision=226539&view=revision - () https://src.chromium.org/viewvc/chrome?revision=226539&view=revision -
References () https://www.exploit-db.com/exploits/40944/ - () https://www.exploit-db.com/exploits/40944/ -

Information

Published : 2013-11-13 15:55

Updated : 2025-04-11 00:51


NVD link : CVE-2013-6627

Mitre link : CVE-2013-6627

CVE.ORG link : CVE-2013-6627


JSON object : View

Products Affected

google

  • chrome
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer