Bug 1014863 (CVE-2013-2919)

Summary: CVE-2013-2919 v8: remote denial of service via memory corruption
Product: [Other] Security Response Reporter: Vincent Danen <vdanen>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED NOTABUG QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: abaron, aortega, apevec, ayoung, bkearney, bleanhar, cbillett, ccoleman, chrisw, cpelland, dallan, dmcphers, drieden, gkotton, hateya, jdetiber, jialiu, jkeck, jokerman, jomara, jorton, katello-bugs, kseifried, lhh, lmeyer, markmc, mmaslano, mmccomas, mmccune, nobody+bgollahe, rbryant, rhos-maint, sclewis, sgallagh, tcallawa, tchollingsworth, tdawson, thrcka, tjay, tkramer, tomckay, tomspur, vdanen, yeylon
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2013-10-24 16:45:25 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 1014865    

Description Vincent Danen 2013-10-03 00:06:39 UTC
Common Vulnerabilities and Exposures assigned an identifier CVE-2013-2919 to
the following vulnerability:

Name: CVE-2013-2919
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2919
Assigned: 20130411
Reference: http://googlechromereleases.blogspot.com/2013/10/stable-channel-update.html
Reference: https://code.google.com/p/chromium/issues/detail?id=282736

Google V8, as used in Google Chrome before 30.0.1599.66, allows remote
attackers to cause a denial of service (memory corruption) or possibly
have unspecified other impact via unknown vectors.

Comment 5 T.C. Hollingsworth 2013-10-08 00:54:49 UTC
Any indication this affects the stable v8 3.14 series we're shipping in Fedora?

The upstream patch seems to be here:
https://code.google.com/p/v8/source/detail?r=16759

But the changes in src/objects.cc don't apply cleanly to 3.14 and the attached test case passes with v8-3.14.5.10-2.

Comment 6 Kurt Seifried 2013-10-24 16:45:25 UTC
The affected code is not present in versions 3.14.x so none of the versions in Fedora and OpenStack, OpenShift, etc. are affected, closing as NOTABUG.