CVE-2013-6631 is a use-after-free vulnerability in the WebRTC libjingle component, specifically affecting the Channel::SendRTCPPacket function. This flaw impacts Google Chrome before version 31.0.1650.48 and other products utilizing WebRTC. With a CVSS score of 7.5, this vulnerability is considered highly severe, allowing unauthenticated remote attackers to cause a denial of service through heap memory corruption, with potential for further unspecified impact. The attack complexity is low. There is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage are minimal, indicating low public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 31.0.1650.47CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
31.0.1650.0CPE matchmatch criteria | cpe:2.3:a:google:chrome:31.0.1650.0:*:*:*:*:*:*:* | ||
31.0.1650.2CPE matchmatch criteria | cpe:2.3:a:google:chrome:31.0.1650.2:*:*:*:*:*:*:* | ||
31.0.1650.3CPE matchmatch criteria | cpe:2.3:a:google:chrome:31.0.1650.3:*:*:*:*:*:*:* | ||
31.0.1650.4CPE matchmatch criteria | cpe:2.3:a:google:chrome:31.0.1650.4:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.