Candidate: CVE-2013-6802 PublicDate: 2013-11-18 05:23:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6802 https://code.google.com/p/chromium/issues/detail?id=319125 https://code.google.com/p/chromium/issues/detail?id=319117 http://www.hppwn2own.com/chrome-nexus-4-samsung-galaxy-s4-falls/ http://googlechromereleases.blogspot.com/2013/11/stable-channel-update_14.html http://googlechromereleases.blogspot.com/2013/11/chrome-for-android-update.html Description: Google Chrome before 31.0.1650.57 allows remote attackers to bypass intended sandbox restrictions by leveraging access to a renderer process, as demonstrated during a Mobile Pwn2Own competition at PacSec 2013, a different vulnerability than CVE-2013-6632. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: chad CVSS: Patches_chromium-browser: upstream_chromium-browser: released (31.0.1650.57) lucid_chromium-browser: ignored (reached end-of-life) precise_chromium-browser: released (31.0.1650.63-0ubuntu0.12.04.1~20131204.1) quantal_chromium-browser: released (31.0.1650.63-0ubuntu0.12.10.1~20131204.1) raring_chromium-browser: released (31.0.1650.63-0ubuntu0.13.04.1~20131204.1) saucy_chromium-browser: released (31.0.1650.63-0ubuntu0.13.10.1~20131204.1) devel_chromium-browser: not-affected (31.0.1650.63-0ubuntu1~20131204.1)