Описание
The drag-and-drop implementation in Google Chrome before 13.0.782.107 on Linux does not properly enforce permissions for files, which allows user-assisted remote attackers to bypass intended access restrictions via unspecified vectors.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | 13.0.782.107~r94237-0ubuntu1 |
| hardy | DNE | |
| lucid | released | 14.0.835.202~r103287-0ubuntu0.10.04.2 |
| maverick | released | 14.0.835.202~r103287-0ubuntu0.10.10.1 |
| natty | released | 14.0.835.202~r103287-0ubuntu0.11.04.1 |
| oneiric | not-affected | 13.0.782.107~r94237-0ubuntu1 |
| upstream | released | 13.0.782.107 |
Показывать по
EPSS
4.3 Medium
CVSS2
Связанные уязвимости
The drag-and-drop implementation in Google Chrome before 13.0.782.107 on Linux does not properly enforce permissions for files, which allows user-assisted remote attackers to bypass intended access restrictions via unspecified vectors.
The drag-and-drop implementation in Google Chrome before 13.0.782.107 ...
The drag-and-drop implementation in Google Chrome before 13.0.782.107 on Linux does not properly enforce permissions for files, which allows user-assisted remote attackers to bypass intended access restrictions via unspecified vectors.
EPSS
4.3 Medium
CVSS2