PT-2008-6799 · Google · Google Chrome

·

CVE-2008-5749

·

Publicado

2008-12-29

·

Atualizado

2024-08-07

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Google Chrome version 1.0.154.36
Description The issue allows remote attackers to execute arbitrary commands via the --renderer-path option in a "chromehtml: URI" API endpoint. A third party disputes this issue, stating that Chrome will ask for user permission and cannot launch the applet even if permission is given.
Recommendations For Google Chrome version 1.0.154.36, consider disabling the --renderer-path option as a temporary workaround until a patch is available. Restrict access to the "chromehtml: URI" API endpoint to minimize the risk of exploitation. Avoid using the --renderer-path option in the affected API endpoint until the issue is resolved.

Exploit

Correção

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-5749

Produtos afetados

Google Chrome