PT-2007-7368 · Google · Google Toolbar

Publicado

2007-12-27

·

Atualizado

2018-10-15

·

CVE-2007-6536

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Google Toolbar versions 4 and 5 beta
Description The issue allows remote attackers to spoof domain names, making it easier to trick users into installing malicious button XML files. This is because the Custom Button Installer dialog presents certain domain names without verifying them, as seen in the "Downloaded from" and "Privacy considerations" sections. This can be exploited by presenting a trusted domain name, such as www.google.com, when the button was actually downloaded from an arbitrary site through an open redirector on the trusted domain.
Recommendations For Google Toolbar versions 4 and 5 beta, consider disabling the Custom Button Installer dialog until a patch is available to prevent the installation of malicious button XML files. Restrict access to the button installation feature to minimize the risk of exploitation. Avoid installing buttons from untrusted sources to reduce the risk of installing malicious files.

Exploit

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2007-6536

Produtos afetados

Google Toolbar