First published: Sat Feb 23 2013(Updated: )
Skia, as used in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, allows remote attackers to cause a denial of service (out-of-bounds read) via vectors related to a "user gesture check for dangerous file downloads."
Credit: cve-coordination@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
openSUSE | =12.1 | |
openSUSE | =12.2 | |
Google Chrome | <25.0.1364.97 | |
Linux Kernel | ||
Microsoft Windows | ||
Google Chrome | <25.0.1364.99 | |
macOS Yosemite |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-0888 has been classified as a high-severity vulnerability due to its potential to cause denial of service through out-of-bounds reads.
To fix CVE-2013-0888, update Google Chrome to version 25.0.1364.97 or higher on affected platforms.
CVE-2013-0888 affects Google Chrome versions earlier than 25.0.1364.97 on Windows and Linux, and earlier than 25.0.1364.99 on Mac OS X.
Yes, CVE-2013-0888 can be exploited by remote attackers without requiring user intervention, leading to a potential denial of service.
CVE-2013-0888 primarily targets users of Google Chrome on Windows, Linux, and Mac OS X.