MEDIUM
common/extensions/sync_helper.cc in Google Chrome before 28.0.1500.71 proceeds with sync operations for NPAPI extensions without checking for a certain plugin permission setting, which might allow remote attackers to trigger unwanted extension changes via unspecified vectors
Published Jul 10, 2013
5.0
MEDIUMCVSS 2.0
EPSS 1.11%
Description
common/extensions/sync_helper.cc in Google Chrome before 28.0.1500.71 proceeds with sync operations for NPAPI extensions without checking for a certain plugin permission setting, which might allow remote attackers to trigger unwanted extension changes via unspecified vectors.
Affected products
No data.
Configuration 1
- 7.0
Configuration 2
OR
- ≤ 28.0.1500.70
- 28.0.1500.0
- 28.0.1500.2
- 28.0.1500.3
- 28.0.1500.4
- 28.0.1500.5
- 28.0.1500.6
- 28.0.1500.8
- 28.0.1500.9
- 28.0.1500.10
- 28.0.1500.11
- 28.0.1500.12
- 28.0.1500.13
- 28.0.1500.14
- 28.0.1500.15
- 28.0.1500.16
- 28.0.1500.17
- 28.0.1500.18
- 28.0.1500.19
- 28.0.1500.20
- 28.0.1500.21
- 28.0.1500.22
- 28.0.1500.23
- 28.0.1500.24
- 28.0.1500.25
- 28.0.1500.26
- 28.0.1500.27
- 28.0.1500.28
- 28.0.1500.29
- 28.0.1500.31
- 28.0.1500.32
- 28.0.1500.33
- 28.0.1500.34
- 28.0.1500.35
- 28.0.1500.36
- 28.0.1500.37
- 28.0.1500.38
- 28.0.1500.39
- 28.0.1500.40
- 28.0.1500.41
- 28.0.1500.42
- 28.0.1500.43
- 28.0.1500.44
- 28.0.1500.45
- 28.0.1500.46
- 28.0.1500.47
- 28.0.1500.48
- 28.0.1500.49
- 28.0.1500.50
- 28.0.1500.51
- 28.0.1500.52
- 28.0.1500.53
- 28.0.1500.54
- 28.0.1500.56
- 28.0.1500.58
- 28.0.1500.59
- 28.0.1500.60
- 28.0.1500.61
- 28.0.1500.62
- 28.0.1500.63
- 28.0.1500.64
- 28.0.1500.66
- 28.0.1500.68
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (0)
No CWE recorded.
References (5)
- http://git.chromium.org/gitweb/?p=chromium/chromium.git%3Ba=commit%3Bh=84ece2d5af0e6f746ca63e483e2dbdbcab8b1e6c x_refsource_CONFIRM
- http://googlechromereleases.blogspot.com/2013/07/stable-channel-update.html x_refsource_CONFIRM
- http://www.debian.org/security/2013/dsa-2724 vendor-advisoryx_refsource_DEBIAN
- https://code.google.com/p/chromium/issues/detail?id=252034 x_refsource_CONFIRM
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17347 vdb-entrysignaturex_refsource_OVAL
| Link | Providers | Tags |
|---|---|---|
| http://git.chromium.org/gitweb/?p=chromium/chromium.git%3Ba=commit%3Bh=84ece2d5af0e6f746ca63e483e2dbdbcab8b1e6c | x_refsource_CONFIRM | |
| http://googlechromereleases.blogspot.com/2013/07/stable-channel-update.html | x_refsource_CONFIRM | |
| http://www.debian.org/security/2013/dsa-2724 | vendor-advisoryx_refsource_DEBIAN | |
| https://code.google.com/p/chromium/issues/detail?id=252034 | x_refsource_CONFIRM | |
| https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17347 | vdb-entrysignaturex_refsource_OVAL |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Chrome
Published Jul 10, 2013
Updated Aug 6, 2024
Reserved Apr 11, 2013
Link CVE-2013-2868
CISA Vulnrichment
Updated n/a