Google Chrome OS before 26.0.1410.57 relies on a Pango pango-utils.c read_config implementation that loads the contents of the .pangorc file in the user's home directory, and the file referenced by the PANGO_RC_FILE environment variable, which allows attackers to bypass intended access restrictions via crafted configuration data.
References
Configurations
Configuration 1 (hide)
|
History
07 Nov 2023, 02:14
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
References | () http://googlechromereleases.blogspot.com/2013/04/chrome-os-stable-channel-update.html - | |
References | () https://code.google.com/p/chromium/issues/detail?id=189250 - |
Information
Published : 2013-04-10 16:55
Updated : 2023-11-07 02:14
NVD link : CVE-2013-0927
Mitre link : CVE-2013-0927
JSON object : View
Products Affected
- chrome_os
CWE
CWE-59
Improper Link Resolution Before File Access ('Link Following')