Use-after-free vulnerability in the Document::finishedParsing function in core/dom/Document.cpp in Blink, as used in Google Chrome before 29.0.1547.57, allows remote attackers to cause a denial of service or possibly have unspecified other impact via an onload event that changes an IFRAME element so that its src attribute is no longer an XML document, leading to unintended garbage collection of this document.
Project Subscriptions
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-2741-1 | chromium-browser security update |
EUVD |
EUVD-2013-2843 | Use-after-free vulnerability in the Document::finishedParsing function in core/dom/Document.cpp in Blink, as used in Google Chrome before 29.0.1547.57, allows remote attackers to cause a denial of service or possibly have unspecified other impact via an onload event that changes an IFRAME element so that its src attribute is no longer an XML document, leading to unintended garbage collection of this document. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Chrome
Published:
Updated: 2024-08-06T15:52:21.107Z
Reserved: 2013-04-11T00:00:00.000Z
Link: CVE-2013-2904
No data.
Status : Deferred
Published: 2013-08-21T12:17:56.900
Modified: 2025-04-11T00:51:21.963
Link: CVE-2013-2904
No data.
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
EUVD