PT-2013-2721 · Gnome+1 · Pango+1
Publicado
2013-04-10
·
Atualizado
2013-04-11
·
CVE-2013-0927
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Google Chrome OS versions prior to 26.0.1410.57
Description
The issue allows attackers to bypass intended access restrictions via crafted configuration data in the .pangorc file or the file referenced by the PANGO RC FILE environment variable. This is due to the Pango pango-utils.c read config implementation loading the contents of these files.
Recommendations
For Google Chrome OS versions prior to 26.0.1410.57, update to version 26.0.1410.57 or later to resolve the issue. As a temporary workaround, consider restricting access to the .pangorc file and the file referenced by the PANGO RC FILE environment variable to minimize the risk of exploitation.
Correção
Link Following
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Google Chrome
Pango