Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cp8g-g2cj-x6hm

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Google Chrome OS before 26.0.1410.57 relies on a Pango pango-utils.c read_config implementation that loads the contents of the .pangorc file in the user's home directory, and the file referenced by the PANGO_RC_FILE environment variable, which allows attackers to bypass intended access restrictions via crafted configuration data.

Google Chrome OS before 26.0.1410.57 relies on a Pango pango-utils.c read_config implementation that loads the contents of the .pangorc file in the user's home directory, and the file referenced by the PANGO_RC_FILE environment variable, which allows attackers to bypass intended access restrictions via crafted configuration data.

EPSS

Процентиль: 41%
0.00192
Низкий

Дефекты

CWE-59

Связанные уязвимости

nvd
почти 13 лет назад

Google Chrome OS before 26.0.1410.57 relies on a Pango pango-utils.c read_config implementation that loads the contents of the .pangorc file in the user's home directory, and the file referenced by the PANGO_RC_FILE environment variable, which allows attackers to bypass intended access restrictions via crafted configuration data.

EPSS

Процентиль: 41%
0.00192
Низкий

Дефекты

CWE-59