Google Chrome OS before 26.0.1410.57 relies on a Pango pango-utils.c read_config implementation that loads the contents of the .pangorc file in the user's home directory, and the file referenced by the PANGO_RC_FILE environment variable, which allows attackers to bypass intended access restrictions via crafted configuration data.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 01:48
Type | Values Removed | Values Added |
---|---|---|
References | () http://git.chromium.org/gitweb/?p=chromiumos/overlays/chromiumos-overlay.git%3Ba=commit%3Bh=fb5a664def6cd34bf7295489ea73e1d989bdd6d0 - | |
References | () http://googlechromereleases.blogspot.com/2013/04/chrome-os-stable-channel-update.html - | |
References | () https://code.google.com/p/chromium/issues/detail?id=189250 - |
07 Nov 2023, 02:14
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
References | () http://googlechromereleases.blogspot.com/2013/04/chrome-os-stable-channel-update.html - | |
References | () https://code.google.com/p/chromium/issues/detail?id=189250 - |
Information
Published : 2013-04-10 16:55
Updated : 2024-11-21 01:48
NVD link : CVE-2013-0927
Mitre link : CVE-2013-0927
CVE.ORG link : CVE-2013-0927
JSON object : View
Products Affected
- chrome_os
CWE
CWE-59
Improper Link Resolution Before File Access ('Link Following')