CVE-2013-0897
published 2013-02-23CVE-2013-0897: Off-by-one error in the PDF functionality in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, allows remote…
PriorityP416medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
1.47%
71.2th percentile
Off-by-one error in the PDF functionality in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, allows remote attackers to cause a denial of service via a crafted document.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | < 25.0.1364.97 | 25.0.1364.97 | |
| chrome | < 25.0.1364.99 | 25.0.1364.99 | |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-1993 Mesa: Multiple integer overflows leading to heap-based bufer overflows
bugzilla·2013-05-10·CVSS 6.8
CVE-2013-1993 [MEDIUM] CVE-2013-1993 Mesa: Multiple integer overflows leading to heap-based bufer overflows
CVE-2013-1993 Mesa: Multiple integer overflows leading to heap-based bufer overflows
Multiple integer overflows leading to heap-based buffer overflows were found in libGLX in Mesa 9.1.1 and earlier
Affected functions: XF86DRIOpenConnection(), XF86DRIGetClientDriverName()
Discussion:
Public via:
http://www.openwall.com/lists/oss-security/2013/05/23/3
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Via RHSA-2013:0898 https://rhn.redhat.com/errata/RHSA-2013-0898.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Via RHSA-2013:0897 https://rhn.redhat.com/errata/RHSA-2013-0897.html
---
External References:
http://www.x.org/wiki/Development/Security/Advisory-2013-05-23
---
(In reply to errata-xmlrpc from c
Bugzilla
CVE-2013-1872 Mesa: Memory corruption (OOB read/write) on intel drivers
bugzilla·2013-03-20·CVSS 6.8
CVE-2013-1872 [MEDIUM] CVE-2013-1872 Mesa: Memory corruption (OOB read/write) on intel drivers
CVE-2013-1872 Mesa: Memory corruption (OOB read/write) on intel drivers
An Out-of-bounds memory read / write flaw was found in Mesa. A remote attacker could use this flaw to crash an application linked against or, potentially, execute arbitrary code via an application linked against Mesa graphics libraries.
References:
https://bugs.freedesktop.org/show_bug.cgi?id=59429
https://code.google.com/p/chromium/issues/detail?id=169054 (private)
https://bugzilla.mozilla.org/show_bug.cgi?id=827106 (private)
Discussion:
Created mesa tracking bugs for this issue
Affects: fedora-all [bug 970010]
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Via RHSA-2013:0897 https://rhn.redhat.com/errata/RHSA-2013-0897.html
http://googlechromereleases.blogspot.com/2013/02/stable-channel-update_21.htmlhttp://lists.opensuse.org/opensuse-updates/2013-03/msg00045.htmlhttps://code.google.com/p/chromium/issues/detail?id=165537https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16153http://googlechromereleases.blogspot.com/2013/02/stable-channel-update_21.htmlhttp://lists.opensuse.org/opensuse-updates/2013-03/msg00045.htmlhttps://code.google.com/p/chromium/issues/detail?id=165537https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16153
2013-02-23
Published