The developer-tools process in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, does not properly restrict privileges during interaction with a connected server, which has unspecified impact and attack vectors.
References
Link | Resource |
---|---|
https://code.google.com/p/chromium/issues/detail?id=170836 | Permissions Required |
http://googlechromereleases.blogspot.com/2013/02/stable-channel-update_21.html | Release Notes Vendor Advisory |
https://code.google.com/p/chromium/issues/detail?id=171065 | Permissions Required |
http://lists.opensuse.org/opensuse-updates/2013-03/msg00045.html | Broken Link Third Party Advisory |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15788 | Third Party Advisory |
Information
Published : 2013-02-23 13:55
Updated : 2022-11-18 11:41
NVD link : CVE-2013-0887
Mitre link : CVE-2013-0887
JSON object : View
CWE
CWE-732
Incorrect Permission Assignment for Critical Resource
Products Affected
apple
- mac_os_x
linux
- linux_kernel
- chrome
microsoft
- windows