Lucene search

K
chromeHttps://chromereleases.googleblog.comGCSA-1077146923148199700
HistoryNov 14, 2013 - 12:00 a.m.

Stable Channel Update

2013-11-1400:00:00
https://chromereleases.googleblog.com
chromereleases.googleblog.com
14

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

0.02 Low

EPSS

Percentile

89.0%

Chrome has been updated to 31.0.1650.57 for Windows, Mac, Linux and Chrome Frame.

Security fixes and rewards:


Congratulations to Pinkie Pie, for reclaiming his title with another impressive exploit!


  • [Ka-po-po-po-pow!!! $50,000*] [319117] [319125] Critical CVE-2013-6632: Multiple memory corruption issues. Credit to Pinkie Pie.

  • This reward was co-sponsored by the HP Zero Day Initiative as part of Mobile Pwn2Own 2013.

Please see the Chromium security page for more detail. Note that the referenced bugs may be kept private until a majority of our users are up to date with the fix.

A full list of changes is available in the SVN log. Interested in switching release channels? Find out how. If you find a new issue, please let us know by filing a bug.

Anthony Laforge
Google Chrome

Affected configurations

Vulners
Node
googlechromeRange<31.0.1650.57
CPENameOperatorVersion
google chromelt31.0.1650.57

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

0.02 Low

EPSS

Percentile

89.0%