PT-2008-6799 · Google · Google Chrome

Nine:Situations:Group

·

Published

2008-12-29

·

Updated

2024-08-07

·

CVE-2008-5749

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Google Chrome version 1.0.154.36
Description The issue allows remote attackers to execute arbitrary commands via the --renderer-path option in a "chromehtml: URI" API endpoint. A third party disputes this issue, stating that Chrome will ask for user permission and cannot launch the applet even if permission is given.
Recommendations For Google Chrome version 1.0.154.36, consider disabling the --renderer-path option as a temporary workaround until a patch is available. Restrict access to the "chromehtml: URI" API endpoint to minimize the risk of exploitation. Avoid using the --renderer-path option in the affected API endpoint until the issue is resolved.

Exploit

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2008-5749

Affected Products

Google Chrome