CVE-2013-2902
Publication date 21 August 2013
Last updated 24 July 2024
Ubuntu priority
Use-after-free vulnerability in the XSLT ProcessingInstruction implementation in Blink, as used in Google Chrome before 29.0.1547.57, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to an applyXSLTransform call involving (1) an HTML document or (2) an xsl:processing-instruction element that is still in the process of loading.
Status
Package | Ubuntu Release | Status |
---|---|---|
chromium-browser | ||
libxslt | ||
Notes
seth-arnold
As of 2013-08-21, I don't know if libxslt needs an update or if this is strictly in chromium-browser.
mdeslaur
fix was in chromium, marking libxslt as not-affected