CVE-2013-6640: Buffer Overflow
The DehoistArrayIndex function in hydrogen-dehoist.cc (aka hydrogen.cc) in Google V8 before 3.22.24.7, as used in Google Chrome before 31.0.1650.63, allows remote attackers to cause a denial of service (out-of-bounds read) via JavaScript code that sets a variable to the value of an array element with a crafted index.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2013-6640?
CVE-2013-6640 is classified as a denial of service vulnerability that allows for out-of-bounds read leading to potential crashes.
How do I fix CVE-2013-6640?
To mitigate CVE-2013-6640, users should upgrade to Google Chrome version 31.0.1650.63 or later.
What versions of Google Chrome are affected by CVE-2013-6640?
CVE-2013-6640 affects Google Chrome versions before 31.0.1650.63.
How does CVE-2013-6640 exploit work?
CVE-2013-6640 exploits a flaw in the DehoistArrayIndex function via malicious JavaScript code that manipulates array elements.
Is CVE-2013-6640 still a threat today?
CVE-2013-6640 is less of a threat today if users have updated to supported versions of Google Chrome or V8.