The WebUI privilege implementation in Google Chrome before 17.0.963.83 does not properly perform isolation, which allows remote attackers to bypass intended access restrictions via unspecified vectors.
References
Configurations
History
21 Nov 2024, 01:29
Type | Values Removed | Values Added |
---|---|---|
References | () http://code.google.com/p/chromium/issues/detail?id=117418 - Vendor Advisory | |
References | () http://googlechromereleases.blogspot.com/2012/03/stable-channel-update_21.html - Release Notes, Vendor Advisory | |
References | () http://lists.opensuse.org/opensuse-security-announce/2012-04/msg00000.html - Mailing List, Third Party Advisory | |
References | () http://osvdb.org/80292 - Broken Link | |
References | () http://secunia.com/advisories/48512 - Not Applicable | |
References | () http://secunia.com/advisories/48527 - Not Applicable | |
References | () http://security.gentoo.org/glsa/glsa-201203-19.xml - Third Party Advisory | |
References | () http://www.securityfocus.com/bid/52674 - Third Party Advisory, VDB Entry | |
References | () http://www.securitytracker.com/id?1026841 - Third Party Advisory, VDB Entry | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/74214 - Third Party Advisory, VDB Entry | |
References | () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15028 - Third Party Advisory |
Information
Published : 2012-03-22 16:55
Updated : 2024-11-21 01:29
NVD link : CVE-2011-3054
Mitre link : CVE-2011-3054
CVE.ORG link : CVE-2011-3054
JSON object : View
Products Affected
- chrome
opensuse
- opensuse
CWE
CWE-269
Improper Privilege Management