CVE-2013-0927

CVSS V2 High 7.5 CVSS V3 None
Description
Google Chrome OS before 26.0.1410.57 relies on a Pango pango-utils.c read_config implementation that loads the contents of the .pangorc file in the user's home directory, and the file referenced by the PANGO_RC_FILE environment variable, which allows attackers to bypass intended access restrictions via crafted configuration data.
Overview
  • CVE ID
  • CVE-2013-0927
  • Assigner
  • cve-coordination@google.com
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2013-04-10T16:55:04
  • Last Modified Date
  • 2013-04-11T04:00:00
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:o:google:chrome_os:*:*:*:*:*:*:*:* 1 OR 26.0.1410.56
cpe:2.3:o:google:chrome_os:26.0.1410.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:google:chrome_os:26.0.1410.1:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:google:chrome_os:26.0.1410.3:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:google:chrome_os:26.0.1410.4:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:google:chrome_os:26.0.1410.5:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:google:chrome_os:26.0.1410.6:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:google:chrome_os:26.0.1410.7:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:google:chrome_os:26.0.1410.8:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:google:chrome_os:26.0.1410.9:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:google:chrome_os:26.0.1410.10:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:google:chrome_os:26.0.1410.11:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:google:chrome_os:26.0.1410.12:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:google:chrome_os:26.0.1410.14:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:google:chrome_os:26.0.1410.15:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:google:chrome_os:26.0.1410.16:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:google:chrome_os:26.0.1410.17:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:google:chrome_os:26.0.1410.18:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:google:chrome_os:26.0.1410.19:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:google:chrome_os:26.0.1410.20:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:google:chrome_os:26.0.1410.21:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:google:chrome_os:26.0.1410.22:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:google:chrome_os:26.0.1410.23:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:google:chrome_os:26.0.1410.24:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:google:chrome_os:26.0.1410.25:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:google:chrome_os:26.0.1410.26:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:google:chrome_os:26.0.1410.27:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:google:chrome_os:26.0.1410.28:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:google:chrome_os:26.0.1410.29:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:google:chrome_os:26.0.1410.30:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:google:chrome_os:26.0.1410.31:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:google:chrome_os:26.0.1410.32:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:google:chrome_os:26.0.1410.33:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:google:chrome_os:26.0.1410.34:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:google:chrome_os:26.0.1410.35:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:google:chrome_os:26.0.1410.36:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:google:chrome_os:26.0.1410.37:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:google:chrome_os:26.0.1410.38:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:google:chrome_os:26.0.1410.39:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:google:chrome_os:26.0.1410.40:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:google:chrome_os:26.0.1410.41:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:google:chrome_os:26.0.1410.42:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:google:chrome_os:26.0.1410.43:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:google:chrome_os:26.0.1410.44:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:google:chrome_os:26.0.1410.45:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:google:chrome_os:26.0.1410.46:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:google:chrome_os:26.0.1410.47:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:google:chrome_os:26.0.1410.48:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:google:chrome_os:26.0.1410.49:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:google:chrome_os:26.0.1410.50:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:google:chrome_os:26.0.1410.51:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:google:chrome_os:26.0.1410.52:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:google:chrome_os:26.0.1410.54:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:google:chrome_os:26.0.1410.55:*:*:*:*:*:*:* 1 OR
CVSS Version 2
  • Version
  • 2.0
  • Vector String
  • AV:N/AC:L/Au:N/C:P/I:P/A:P
  • Access Vector
  • NETWORK
  • Access Compatibility
  • LOW
  • Authentication
  • NONE
  • Confidentiality Impact
  • PARTIAL
  • Integrity Impact
  • PARTIAL
  • Availability Impact
  • PARTIAL
  • Base Score
  • 7.5
  • Severity
  • HIGH
  • Exploitability Score
  • 10
  • Impact Score
  • 6.4
History
Created Old Value New Value Data Type Notes
2022-05-10 10:46:02 Added to TrackCVE