PT-2010-2409 · Google · Google Chrome

Inferno

·

Published

2010-02-18

·

Updated

2017-09-19

·

CVE-2010-0657

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 4.0.249.78
Description The issue allows user-assisted remote attackers to execute arbitrary programs or obtain sensitive information by tricking a user into creating a crafted shortcut, due to insufficient encoding, escaping, and quoting for the URL in the --app argument in a desktop shortcut.
Recommendations For versions prior to 4.0.249.78, update to version 4.0.249.78 or later to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2010-0657

Affected Products

Google Chrome