Google Chrome OS before 26.0.1410.57 relies on a Pango pango-utils.c read_config implementation that loads the contents of the .pangorc file in the user's home directory, and the file referenced by the PANGO_RC_FILE environment variable, which allows attackers to bypass intended access restrictions via crafted configuration data.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2013-04-10 09:55
Updated : 2013-04-10 21:00
NVD link : CVE-2013-0927
Mitre link : CVE-2013-0927
JSON object : View
CWE
CWE-59
Improper Link Resolution Before File Access ('Link Following')
Products Affected
- chrome_os