The DehoistArrayIndex function in hydrogen-dehoist.cc (aka hydrogen.cc) in Google V8 before 3.22.24.7, as used in Google Chrome before 31.0.1650.63, allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via JavaScript code that sets the value of an array element with a crafted index.
The MITRE CVE dictionary describes this issue as:
Find out more about CVE-2013-6639 from the MITRE CVE dictionary dictionary and NIST NVD.
Base Score | 6.8 |
---|---|
Base Metrics | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Access Vector | Network |
Access Complexity | Medium |
Authentication | None |
Confidentiality Impact | Partial |
Integrity Impact | Partial |
Availability Impact | Partial |
Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).
Platform | Errata | Release Date |
---|---|---|
Red Hat Software Collections 1 for Red Hat Enterprise Linux 6 (v8314-v8) | RHSA-2014:1744 | 2014-10-30 |
Red Hat Software Collections 1 for Red Hat Enterprise Linux 7 (v8314-v8) | RHSA-2014:1744 | 2014-10-30 |
Platform | Package | State |
---|---|---|
Red Hat Subscription Asset Manager 1 | v8 | Will not fix |
Red Hat Subscription Asset Manager 1 | ruby193-v8 | Will not fix |
Red Hat Satellite 6 | v8 | Will not fix |
Red Hat OpenShift Enterprise 2 | v8 | Will not fix |
Red Hat OpenShift Enterprise 1 | ruby193-v8 | Will not fix |
Red Hat Enterprise Linux OpenStack Platform 4.0 | v8 | Will not fix |
Red Hat Enterprise Linux OpenStack Platform 4.0 | ruby193-v8 | Will not fix |
Red Hat Enterprise Linux OpenStack Platform 3.0 | v8 | Will not fix |
Red Hat Enterprise Linux OpenStack Platform 3.0 | ruby193-v8 | Will not fix |