CVE-2011-3054

The WebUI privilege implementation in Google Chrome before 17.0.963.83 does not properly perform isolation, which allows remote attackers to bypass intended access restrictions via unspecified vectors.
References
Link Resource
http://code.google.com/p/chromium/issues/detail?id=117418 Vendor Advisory
http://googlechromereleases.blogspot.com/2012/03/stable-channel-update_21.html Release Notes Vendor Advisory
http://lists.opensuse.org/opensuse-security-announce/2012-04/msg00000.html Mailing List Third Party Advisory
http://osvdb.org/80292 Broken Link
http://secunia.com/advisories/48512 Not Applicable
http://secunia.com/advisories/48527 Not Applicable
http://security.gentoo.org/glsa/glsa-201203-19.xml Third Party Advisory
http://www.securityfocus.com/bid/52674 Third Party Advisory VDB Entry
http://www.securitytracker.com/id?1026841 Third Party Advisory VDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/74214 Third Party Advisory VDB Entry
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15028 Third Party Advisory
http://code.google.com/p/chromium/issues/detail?id=117418 Vendor Advisory
http://googlechromereleases.blogspot.com/2012/03/stable-channel-update_21.html Release Notes Vendor Advisory
http://lists.opensuse.org/opensuse-security-announce/2012-04/msg00000.html Mailing List Third Party Advisory
http://osvdb.org/80292 Broken Link
http://secunia.com/advisories/48512 Not Applicable
http://secunia.com/advisories/48527 Not Applicable
http://security.gentoo.org/glsa/glsa-201203-19.xml Third Party Advisory
http://www.securityfocus.com/bid/52674 Third Party Advisory VDB Entry
http://www.securitytracker.com/id?1026841 Third Party Advisory VDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/74214 Third Party Advisory VDB Entry
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15028 Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:opensuse:opensuse:12.1:*:*:*:*:*:*:*

History

21 Nov 2024, 01:29

Type Values Removed Values Added
References () http://code.google.com/p/chromium/issues/detail?id=117418 - Vendor Advisory () http://code.google.com/p/chromium/issues/detail?id=117418 - Vendor Advisory
References () http://googlechromereleases.blogspot.com/2012/03/stable-channel-update_21.html - Release Notes, Vendor Advisory () http://googlechromereleases.blogspot.com/2012/03/stable-channel-update_21.html - Release Notes, Vendor Advisory
References () http://lists.opensuse.org/opensuse-security-announce/2012-04/msg00000.html - Mailing List, Third Party Advisory () http://lists.opensuse.org/opensuse-security-announce/2012-04/msg00000.html - Mailing List, Third Party Advisory
References () http://osvdb.org/80292 - Broken Link () http://osvdb.org/80292 - Broken Link
References () http://secunia.com/advisories/48512 - Not Applicable () http://secunia.com/advisories/48512 - Not Applicable
References () http://secunia.com/advisories/48527 - Not Applicable () http://secunia.com/advisories/48527 - Not Applicable
References () http://security.gentoo.org/glsa/glsa-201203-19.xml - Third Party Advisory () http://security.gentoo.org/glsa/glsa-201203-19.xml - Third Party Advisory
References () http://www.securityfocus.com/bid/52674 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/52674 - Third Party Advisory, VDB Entry
References () http://www.securitytracker.com/id?1026841 - Third Party Advisory, VDB Entry () http://www.securitytracker.com/id?1026841 - Third Party Advisory, VDB Entry
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/74214 - Third Party Advisory, VDB Entry () https://exchange.xforce.ibmcloud.com/vulnerabilities/74214 - Third Party Advisory, VDB Entry
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15028 - Third Party Advisory () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15028 - Third Party Advisory

Information

Published : 2012-03-22 16:55

Updated : 2024-11-21 01:29


NVD link : CVE-2011-3054

Mitre link : CVE-2011-3054

CVE.ORG link : CVE-2011-3054


JSON object : View

Products Affected

google

  • chrome

opensuse

  • opensuse
CWE
CWE-269

Improper Privilege Management