Description
Google Chrome OS before 26.0.1410.57 relies on a Pango pango-utils.c read_config implementation that loads the contents of the .pangorc file in the user's home directory, and the file referenced by the PANGO_RC_FILE environment variable, which allows attackers to bypass intended access restrictions via crafted configuration data.
References (3)
Core 3
Core References
Release Notes, Vendor Advisory x_refsource_confirm
http://googlechromereleases.blogspot.com/2013/04/chrome-os-stable-channel-update.html
Issue Tracking x_refsource_confirm
https://code.google.com/p/chromium/issues/detail?id=189250
Various Sources x_refsource_confirm
http://git.chromium.org/gitweb/?p=chromiumos/overlays/chromiumos-overlay.git%3Ba=commit%3Bh=fb5a664def6cd34bf7295489ea73e1d989bdd6d0
Scores
EPSS
0.0087
EPSS Percentile
54.1%
Details
CWE
CWE-59
Status
published
Products (50)
google/chrome_os
26.0.1410.0
google/chrome_os
26.0.1410.1
google/chrome_os
26.0.1410.3
google/chrome_os
26.0.1410.4
google/chrome_os
26.0.1410.5
google/chrome_os
26.0.1410.6
google/chrome_os
26.0.1410.7
google/chrome_os
26.0.1410.8
google/chrome_os
26.0.1410.9
google/chrome_os
26.0.1410.10
... and 40 more
Published
Apr 10, 2013
Tracked Since
Feb 18, 2026