PT-2014-3162 · Google+1 · Google Chrome+1

Published

2014-03-03

·

Updated

2017-01-07

·

CVE-2013-6664

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 33.0.1750.146
Description A use-after-free issue in the FormAssociatedElement::formRemovedFromTree function in core/html/FormAssociatedElement.cpp in Blink allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving FORM elements, such as the use of the speech-recognition feature.
Recommendations For versions prior to 33.0.1750.146, update to version 33.0.1750.146 or later to resolve the issue. As a temporary workaround, consider disabling the speech-recognition feature until a patch is available. Restrict access to FORM elements to minimize the risk of exploitation.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2014-1282
CVE-2013-6664
DSA-2883-1
MGASA-2014-0121

Affected Products

Alt Linux
Google Chrome