Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2013-2866

Опубликовано: 19 июн. 2013
Источник: ubuntu
Приоритет: medium
CVSS2: 4.3

Описание

The Flash plug-in in Google Chrome before 27.0.1453.116, as used on Google Chrome OS before 27.0.1453.116 and separately, does not properly determine whether a user wishes to permit camera or microphone access by a Flash application, which allows remote attackers to obtain sensitive information from a machine's physical environment via a clickjacking attack, as demonstrated by an attack using a crafted Cascading Style Sheets (CSS) opacity property.

РелизСтатусПримечание
devel

not-affected

lucid

not-affected

precise

not-affected

quantal

not-affected

raring

not-affected

upstream

released

27.0.1453.116

Показывать по

4.3 Medium

CVSS2

Связанные уязвимости

nvd
больше 12 лет назад

The Flash plug-in in Google Chrome before 27.0.1453.116, as used on Google Chrome OS before 27.0.1453.116 and separately, does not properly determine whether a user wishes to permit camera or microphone access by a Flash application, which allows remote attackers to obtain sensitive information from a machine's physical environment via a clickjacking attack, as demonstrated by an attack using a crafted Cascading Style Sheets (CSS) opacity property.

debian
больше 12 лет назад

The Flash plug-in in Google Chrome before 27.0.1453.116, as used on Go ...

github
больше 3 лет назад

The Flash plug-in in Google Chrome before 27.0.1453.116, as used on Google Chrome OS before 27.0.1453.116 and separately, does not properly determine whether a user wishes to permit camera or microphone access by a Flash application, which allows remote attackers to obtain sensitive information from a machine's physical environment via a clickjacking attack, as demonstrated by an attack using a crafted Cascading Style Sheets (CSS) opacity property.

4.3 Medium

CVSS2