Configuration Loading Vulnerability in Google Chrome OS
CVE-2013-0927

Currently unrated

Key Information:

Vendor
Google
Status
Vendor
CVE Published:
10 April 2013

Summary

Google Chrome OS versions prior to 26.0.1410.57 are affected by a vulnerability that enables attackers to circumvent access controls by exploiting the read_config functionality in the Pango library. This flaw occurs due to the loading of user-specific configuration files, such as .pangorc and those specified by the PANGO_RC_FILE environment variable. Malicious actors can create crafted configuration data that could lead to unauthorized actions or access.

References

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.