CVE-2013-0927

Severity CVSS v4.0:
Pending analysis
Type:
CWE-59 Link Following
Publication date:
10/04/2013
Last modified:
11/04/2025

Description

Google Chrome OS before 26.0.1410.57 relies on a Pango pango-utils.c read_config implementation that loads the contents of the .pangorc file in the user's home directory, and the file referenced by the PANGO_RC_FILE environment variable, which allows attackers to bypass intended access restrictions via crafted configuration data.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:google:chrome_os:*:*:*:*:*:*:*:* 26.0.1410.56 (including)
cpe:2.3:o:google:chrome_os:26.0.1410.0:*:*:*:*:*:*:*
cpe:2.3:o:google:chrome_os:26.0.1410.1:*:*:*:*:*:*:*
cpe:2.3:o:google:chrome_os:26.0.1410.3:*:*:*:*:*:*:*
cpe:2.3:o:google:chrome_os:26.0.1410.4:*:*:*:*:*:*:*
cpe:2.3:o:google:chrome_os:26.0.1410.5:*:*:*:*:*:*:*
cpe:2.3:o:google:chrome_os:26.0.1410.6:*:*:*:*:*:*:*
cpe:2.3:o:google:chrome_os:26.0.1410.7:*:*:*:*:*:*:*
cpe:2.3:o:google:chrome_os:26.0.1410.8:*:*:*:*:*:*:*
cpe:2.3:o:google:chrome_os:26.0.1410.9:*:*:*:*:*:*:*
cpe:2.3:o:google:chrome_os:26.0.1410.10:*:*:*:*:*:*:*
cpe:2.3:o:google:chrome_os:26.0.1410.11:*:*:*:*:*:*:*
cpe:2.3:o:google:chrome_os:26.0.1410.12:*:*:*:*:*:*:*
cpe:2.3:o:google:chrome_os:26.0.1410.14:*:*:*:*:*:*:*
cpe:2.3:o:google:chrome_os:26.0.1410.15:*:*:*:*:*:*:*